{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-04T10:14:25.288","vulnerabilities":[{"cve":{"id":"CVE-2015-5346","sourceIdentifier":"secalert@redhat.com","published":"2016-02-25T01:59:02.167","lastModified":"2026-05-06T22:30:45.220","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java."},{"lang":"es","value":"Vulnerabilidad de fijación de sesión en Apache Tomcat 7.x en versiones anteriores a 7.0.66, 8.x en versiones anteriores a 8.0.30 y 9.x en versiones anteriores a 9.0.0.M2, cuando se utilizan configuraciones de sesión diferentes para despliegues de múltiples versiones de la misma aplicación web, podría permitir a atacantes remotos secuestrar sesiones web aprovechando el uso de un campo requestedSessionSSL para una petición no intencionada, relacionado con CoyoteAdapter.java y Request.java."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*","matchCriteriaId":"33E9607B-4D28-460D-896B-E4B7FA22441E"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.2:beta:*:*:*:*:*:*","matchCriteriaId":"81A31CA0-A209-4C49-AA06-C38E165E5B68"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.4:beta:*:*:*:*:*:*","matchCriteriaId":"0AA563BF-A67A-477D-956A-167ABEF885C5"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.5:beta:*:*:*:*:*:*","matchCriteriaId":"6F1B937B-57E0-4E88-9E39-39012A924525"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.6:*:*:*:*:*:*:*","matchCriteriaId":"8980E61E-27BE-4858-82B3-C0E8128AF521"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.10:*:*:*:*:*:*:*","matchCriteriaId":"A9731BAA-4C6C-4259-B786-F577D8A90FA1"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.11:*:*:*:*:*:*:*","matchCriteriaId":"1F74A421-D019-4248-84B8-C70D4D9A8A95"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.12:*:*:*:*:*:*:*","matchCriteriaId":"2BA27FF9-4C66-4E17-95C0-1CB2DAA6AFC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.14:*:*:*:*:*:*:*","matchCriteriaId":"305688F2-50A6-41FB-8614-BC589DB9A789"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.16:*:*:*:*:*:*:*","matchCriteriaId":"25966344-15D5-4101-9346-B06BFD2DFFF5"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.19:*:*:*:*:*:*:*","matchCriteriaId":"0D4F710E-06EA-48F4-AC6A-6F143950F015"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.20:*:*:*:*:*:*:*","matchCriteriaId":"2C4936C2-0B2D-4C44-98C3-443090965F5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.21:*:*:*:*:*:*:*","matchCriteriaId":"48453405-2319-4327-9F4C-6F70B49452C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.22:*:*:*:*:*:*:*","matchCriteriaId":"49DD9544-6424-41A6-AEC0-EC19B8A10E71"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.23:*:*:*:*:*:*:*","matchCriteriaId":"E4670E65-2E11-49A4-B661-57C2F60D411F"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.25:*:*:*:*:*:*:*","matchCriteriaId":"31002A23-4788-4BC7-AE11-A3C2AA31716D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.26:*:*:*:*:*:*:*","matchCriteriaId":"7144EDDF-8265-4642-8EEB-ED52527E0A26"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.27:*:*:*:*:*:*:*","matchCriteriaId":"DF06B5C1-B9DD-4673-A101-56E1E593ACDD"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.28:*:*:*:*:*:*:*","matchCriteriaId":"7D731065-626B-4425-8E49-F708DD457824"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.29:*:*:*:*:*:*:*","matchCriteriaId":"B3D850EA-E537-42C8-93B9-96E15CB26747"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.30:*:*:*:*:*:*:*","matchCriteriaId":"E037DA05-2BEF-4F64-B8BB-307247B6A05C"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.32:*:*:*:*:*:*:*","matchCriteriaId":"D395D95B-1F4A-420E-A0F6-609360AF7B69"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.33:*:*:*:*:*:*:*","matchCriteriaId":"9BD221BA-0AB6-4972-8AD9-5D37AC07762F"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.34:*:*:*:*:*:*:*","matchCriteriaId":"E55B6565-96CB-4F6A-9A80-C3FB82F30546"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.35:*:*:*:*:*:*:*","matchCriteriaId":"D3300AFE-49A4-4904-B9A0-5679F09FA01E"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.37:*:*:*:*:*:*:*","matchCriteriaId":"7BD93669-1B30-4BF8-AD7D-F60DD8D63CC8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.39:*:*:*:*:*:*:*","matchCriteriaId":"B8C8C97F-6C9D-4647-AB8A-ADAA5536DDE2"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.40:*:*:*:*:*:*:*","matchCriteriaId":"2C6109D1-BC36-40C5-A02A-7AEBC949BAC0"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*","matchCriteriaId":"DA8A7333-B4C3-4876-AE01-62F2FD315504"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*","matchCriteriaId":"92993E23-D805-407B-8B87-11CEEE8B212F"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*","matchCriteriaId":"6AA28D3A-3EE5-4F90-B8F5-4943F7607DA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*","matchCriteriaId":"C947E549-2459-4AFB-84A7-36BDA30B5F29"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.52:*:*:*:*:*:*:*","matchCriteriaId":"5D55DF79-F9BE-4907-A4D8-96C4B11189ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.53:*:*:*:*:*:*:*","matchCriteriaId":"14AB5787-82D7-4F78-BE93-4556AB7A7D0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:*","matchCriteriaId":"F8E9453E-BC9B-4F77-85FA-BA15AC55C245"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:*","matchCriteriaId":"A7EF0518-73F9-47DB-8946-A8334936BEFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:*","matchCriteriaId":"95AA8778-7833-4572-A71B-5FD89938CE94"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:*","matchCriteriaId":"242E47CE-EF69-4F8F-AB40-5AF2811674CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:*","matchCriteriaId":"CDA1555C-E55A-4E14-B786-BFEE3F09220B"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:*","matchCriteriaId":"F8075E9A-DA7F-4A0B-8B4D-0CD951369111"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:*","matchCriteriaId":"335A5320-6086-4B45-9903-82F6F92A584F"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:*","matchCriteriaId":"46B33408-C2E2-4E7C-9334-6AB98F13468C"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:*","matchCriteriaId":"9F036676-9EFB-4A92-828E-A38905D594E2"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:*","matchCriteriaId":"E9728EE8-6029-4DF3-942E-E4ACC09111A3"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*","matchCriteriaId":"4752862B-7D26-4285-B8A0-CF082C758353"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*","matchCriteriaId":"58EA7199-3373-4F97-9907-3A479A02155E"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.0:rc3:*:*:*:*:*:*","matchCriteriaId":"F963D737-2E95-4D7C-92C7-DACF3F36D1E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*","matchCriteriaId":"2BBBC5EA-012C-4C5D-A61B-BAF134B300DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*","matchCriteriaId":"2A358FDF-C249-4D7A-9445-8B9E7D9D40AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:*","matchCriteriaId":"AFF96F96-34DB-4EB3-BF59-11220673FA26"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.11:*:*:*:*:*:*:*","matchCriteriaId":"701424A2-BB06-44B5-B468-7164E4F95529"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.12:*:*:*:*:*:*:*","matchCriteriaId":"1BA6388C-5B6E-4651-8AE3-EBCCF61C27E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.14:*:*:*:*:*:*:*","matchCriteriaId":"8F9A5B7E-33A9-4651-9BE1-371A0064B661"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.15:*:*:*:*:*:*:*","matchCriteriaId":"F99252E8-A59C-48E1-B251-718D7FB3E399"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.17:*:*:*:*:*:*:*","matchCriteriaId":"4E0DDEF6-A8EE-46C4-A046-A1F26E7C4E87"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.18:*:*:*:*:*:*:*","matchCriteriaId":"14B38892-9C00-4510-B7BA-F2A8F2CACCAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.20:*:*:*:*:*:*:*","matchCriteriaId":"7409B064-D43E-489E-AEC6-0A767FB21737"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.21:*:*:*:*:*:*:*","matchCriteriaId":"F019268F-80C4-48FE-8164-E9DA0A3BAFF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.22:*:*:*:*:*:*:*","matchCriteriaId":"1EFBD214-FCFE-4F04-A903-66EFDA764B9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.23:*:*:*:*:*:*:*","matchCriteriaId":"425D86B3-6BB9-410D-8125-F7CF87290AD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.24:*:*:*:*:*:*:*","matchCriteriaId":"3EE3BB0D-1002-41E4-9BE8-875D97330057"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.26:*:*:*:*:*:*:*","matchCriteriaId":"6622472B-8644-4D45-A54B-A215C3D64B83"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.27:*:*:*:*:*:*:*","matchCriteriaId":"B338F95B-2924-435B-827F-E64420A93244"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.28:*:*:*:*:*:*:*","matchCriteriaId":"209D1349-7740-4DBE-80A5-E6343C62BAB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:8.0.29:*:*:*:*:*:*:*","matchCriteriaId":"09E77C24-C265-403D-A193-B3739713F6B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*","matchCriteriaId":"9D0689FE-4BC0-4F53-8C79-34B21F9B86C2"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*","matchCriteriaId":"B6B7CAD7-9D4E-4FDB-88E3-1E583210A01F"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","matchCriteriaId":"B5A6F2F3-4894-4392-8296-3B8DD2679084"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*","matchCriteriaId":"E88A537F-F4D0-46B9-9E37-965233C2A355"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","matchCriteriaId":"F7016A2A-8365-4F1A-89A2-7A19F2BCAE5B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"}]}]}],"references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html","source":"secalert@redhat.com"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html","source":"secalert@redhat.com"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html","source":"secalert@redhat.com"},{"url":"http://packetstormsecurity.com/files/135890/Apache-Tomcat-Session-Fixation.html","source":"secalert@redhat.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-1089.html","source":"secalert@redhat.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2046.html","source":"secalert@redhat.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2807.html","source":"secalert@redhat.com"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2808.html","source":"secalert@redhat.com"},{"url":"http://seclists.org/bugtraq/2016/Feb/143","source":"secalert@redhat.com"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1713184","source":"secalert@redhat.com"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1713185","source":"secalert@redhat.com"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1713187","source":"secalert@redhat.com"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1723414","source":"secalert@redhat.com"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1723506","source":"secalert@redhat.com"},{"url":"http://tomcat.apache.org/security-7.html","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://tomcat.apache.org/security-8.html","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://tomcat.apache.org/security-9.html","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://www.debian.org/security/2016/dsa-3530","source":"secalert@redhat.com"},{"url":"http://www.debian.org/security/2016/dsa-3552","source":"secalert@redhat.com"},{"url":"http://www.debian.org/security/2016/dsa-3609","source":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","source":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html","source":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html","source":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/83323","source":"secalert@redhat.com"},{"url":"http://www.securitytracker.com/id/1035069","source":"secalert@redhat.com"},{"url":"http://www.ubuntu.com/usn/USN-3024-1","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2016:1087","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2016:1088","source":"secalert@redhat.com"},{"url":"https://bto.bluecoat.com/security-advisory/sa118","source":"secalert@redhat.com"},{"url":"https://bz.apache.org/bugzilla/show_bug.cgi?id=58809","source":"secalert@redhat.com"},{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442","source":"secalert@redhat.com"},{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626","source":"secalert@redhat.com"},{"url":"https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","source":"secalert@redhat.com"},{"url":"https://security.gentoo.org/glsa/201705-09","source":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20180531-0001/","source":"secalert@redhat.com"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/135890/Apache-Tomcat-Session-Fixation.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-1089.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2046.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2807.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-2808.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/bugtraq/2016/Feb/143","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1713184","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1713185","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1713187","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1723414","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://svn.apache.org/viewvc?view=revision&revision=1723506","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://tomcat.apache.org/security-7.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://tomcat.apache.org/security-8.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://tomcat.apache.org/security-9.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.debian.org/security/2016/dsa-3530","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.debian.org/security/2016/dsa-3552","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.debian.org/security/2016/dsa-3609","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/83323","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1035069","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.ubuntu.com/usn/USN-3024-1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2016:1087","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2016:1088","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bto.bluecoat.com/security-advisory/sa118","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bz.apache.org/bugzilla/show_bug.cgi?id=58809","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150442","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158626","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/201705-09","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20180531-0001/","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorComment":"<a href=\"https://cwe.mitre.org/data/definitions/384.html\">CWE-384: Session Fixation</a>"}}]}