CVE-2007-3385
tomcat handling of cookie values
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
Apache Tomcat 6.0.0 hasta 6.0.13, 5.5.0 hasta 5.5.24, 5.0.0 hasta 5.0.30, 4.1.0 hasta 4.1.36, y 3.3 hasta 3.3.2 no trata adecuadamente la secuencia de caracteres \" en un valor de cookie, lo cual podría provocar que información sensible como los IDs de sesión sean filtradas a atacantes remotos, así como habilitar ataques de secuestro de sesión.
Multiple security risks exist in Apache Tomcat as included with CA Cohesion and products that contain CA Cohesion. These include, but are not limited to, arbitrary command execution. Affected products include CA Cohesion Application Configuration Manager 4.5, CA CMDB Application Server 11.1, and Unicenter Service Desk 11.2.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-06-25 CVE Reserved
- 2007-08-14 CVE Published
- 2024-08-07 CVE Updated
- 2025-07-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (53)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.kb.cert.org/vuls/id/993544 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 3.3 Search vendor "Apache" for product "Tomcat" and version "3.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 3.3.1 Search vendor "Apache" for product "Tomcat" and version "3.3.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 3.3.1a Search vendor "Apache" for product "Tomcat" and version "3.3.1a" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 3.3.2 Search vendor "Apache" for product "Tomcat" and version "3.3.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.0 Search vendor "Apache" for product "Tomcat" and version "4.1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.1 Search vendor "Apache" for product "Tomcat" and version "4.1.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.2 Search vendor "Apache" for product "Tomcat" and version "4.1.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.3 Search vendor "Apache" for product "Tomcat" and version "4.1.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.3 Search vendor "Apache" for product "Tomcat" and version "4.1.3" | beta |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.9 Search vendor "Apache" for product "Tomcat" and version "4.1.9" | beta |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.10 Search vendor "Apache" for product "Tomcat" and version "4.1.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.15 Search vendor "Apache" for product "Tomcat" and version "4.1.15" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.24 Search vendor "Apache" for product "Tomcat" and version "4.1.24" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.28 Search vendor "Apache" for product "Tomcat" and version "4.1.28" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.31 Search vendor "Apache" for product "Tomcat" and version "4.1.31" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 4.1.36 Search vendor "Apache" for product "Tomcat" and version "4.1.36" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.0 Search vendor "Apache" for product "Tomcat" and version "5.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.1 Search vendor "Apache" for product "Tomcat" and version "5.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.2 Search vendor "Apache" for product "Tomcat" and version "5.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.3 Search vendor "Apache" for product "Tomcat" and version "5.0.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.4 Search vendor "Apache" for product "Tomcat" and version "5.0.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.5 Search vendor "Apache" for product "Tomcat" and version "5.0.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.6 Search vendor "Apache" for product "Tomcat" and version "5.0.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.7 Search vendor "Apache" for product "Tomcat" and version "5.0.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.8 Search vendor "Apache" for product "Tomcat" and version "5.0.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.9 Search vendor "Apache" for product "Tomcat" and version "5.0.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.10 Search vendor "Apache" for product "Tomcat" and version "5.0.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.11 Search vendor "Apache" for product "Tomcat" and version "5.0.11" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.12 Search vendor "Apache" for product "Tomcat" and version "5.0.12" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.13 Search vendor "Apache" for product "Tomcat" and version "5.0.13" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.14 Search vendor "Apache" for product "Tomcat" and version "5.0.14" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.15 Search vendor "Apache" for product "Tomcat" and version "5.0.15" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.16 Search vendor "Apache" for product "Tomcat" and version "5.0.16" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.17 Search vendor "Apache" for product "Tomcat" and version "5.0.17" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.18 Search vendor "Apache" for product "Tomcat" and version "5.0.18" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.19 Search vendor "Apache" for product "Tomcat" and version "5.0.19" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.21 Search vendor "Apache" for product "Tomcat" and version "5.0.21" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.22 Search vendor "Apache" for product "Tomcat" and version "5.0.22" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.23 Search vendor "Apache" for product "Tomcat" and version "5.0.23" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.24 Search vendor "Apache" for product "Tomcat" and version "5.0.24" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.25 Search vendor "Apache" for product "Tomcat" and version "5.0.25" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.26 Search vendor "Apache" for product "Tomcat" and version "5.0.26" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.27 Search vendor "Apache" for product "Tomcat" and version "5.0.27" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.28 Search vendor "Apache" for product "Tomcat" and version "5.0.28" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.29 Search vendor "Apache" for product "Tomcat" and version "5.0.29" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.0.30 Search vendor "Apache" for product "Tomcat" and version "5.0.30" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.0 Search vendor "Apache" for product "Tomcat" and version "5.5.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.1 Search vendor "Apache" for product "Tomcat" and version "5.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.2 Search vendor "Apache" for product "Tomcat" and version "5.5.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.3 Search vendor "Apache" for product "Tomcat" and version "5.5.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.4 Search vendor "Apache" for product "Tomcat" and version "5.5.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.5 Search vendor "Apache" for product "Tomcat" and version "5.5.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.6 Search vendor "Apache" for product "Tomcat" and version "5.5.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.7 Search vendor "Apache" for product "Tomcat" and version "5.5.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.8 Search vendor "Apache" for product "Tomcat" and version "5.5.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.9 Search vendor "Apache" for product "Tomcat" and version "5.5.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.10 Search vendor "Apache" for product "Tomcat" and version "5.5.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.11 Search vendor "Apache" for product "Tomcat" and version "5.5.11" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.12 Search vendor "Apache" for product "Tomcat" and version "5.5.12" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.13 Search vendor "Apache" for product "Tomcat" and version "5.5.13" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.14 Search vendor "Apache" for product "Tomcat" and version "5.5.14" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.15 Search vendor "Apache" for product "Tomcat" and version "5.5.15" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.16 Search vendor "Apache" for product "Tomcat" and version "5.5.16" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.17 Search vendor "Apache" for product "Tomcat" and version "5.5.17" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.18 Search vendor "Apache" for product "Tomcat" and version "5.5.18" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.19 Search vendor "Apache" for product "Tomcat" and version "5.5.19" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.20 Search vendor "Apache" for product "Tomcat" and version "5.5.20" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.21 Search vendor "Apache" for product "Tomcat" and version "5.5.21" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.22 Search vendor "Apache" for product "Tomcat" and version "5.5.22" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.23 Search vendor "Apache" for product "Tomcat" and version "5.5.23" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 5.5.24 Search vendor "Apache" for product "Tomcat" and version "5.5.24" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.0 Search vendor "Apache" for product "Tomcat" and version "6.0.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.1 Search vendor "Apache" for product "Tomcat" and version "6.0.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.2 Search vendor "Apache" for product "Tomcat" and version "6.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.3 Search vendor "Apache" for product "Tomcat" and version "6.0.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.4 Search vendor "Apache" for product "Tomcat" and version "6.0.4" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.5 Search vendor "Apache" for product "Tomcat" and version "6.0.5" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.6 Search vendor "Apache" for product "Tomcat" and version "6.0.6" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.7 Search vendor "Apache" for product "Tomcat" and version "6.0.7" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.8 Search vendor "Apache" for product "Tomcat" and version "6.0.8" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.9 Search vendor "Apache" for product "Tomcat" and version "6.0.9" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.10 Search vendor "Apache" for product "Tomcat" and version "6.0.10" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.11 Search vendor "Apache" for product "Tomcat" and version "6.0.11" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.12 Search vendor "Apache" for product "Tomcat" and version "6.0.12" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 6.0.13 Search vendor "Apache" for product "Tomcat" and version "6.0.13" | - |
Affected
|