Sploitus

CVE-2015-5346

No indexed exploits for CVE-2015-5346 yet

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

Apache Tomcat
= 7.0.0, 7.0.2, 7.0.4, 7.0.5, 7.0.6, 7.0.10, 7.0.11, 7.0.12, 7.0.14, 7.0.16, 7.0.19, 7.0.20, 7.0.21, 7.0.22, 7.0.23, 7.0.25, 7.0.26, 7.0.27, 7.0.28, 7.0.29, 7.0.30, 7.0.32, 7.0.33, 7.0.34, 7.0.35, 7.0.37, 7.0.39, 7.0.40, 7.0.41, 7.0.42, 7.0.47, 7.0.50, 7.0.52, 7.0.53, 7.0.54, 7.0.55, 7.0.56, 7.0.57, 7.0.59, 7.0.61
Fix
Available
CVSS 3.0
8.1 HIGH
EPSS
10.6% (95th percentile)
NVD status
Modified
Published
2016-02-25
CVE-2015-5346 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2015-5346 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2015-5346 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.