CVE-2008-0128

NameCVE-2008-0128
DescriptionThe SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1468-1
NVD severitymedium (attack range: remote)
Debian/oldoldstablenot known to be vulnerable.
Debian/oldstablenot known to be vulnerable.
Debian/stablenot known to be vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot known to be vulnerable.

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tomcat5source(unstable)(unfixed)unimportant
tomcat5.5source(unstable)5.5.23-1low
tomcat5.5sourceetch5.5.20-2etch2mediumDSA-1468-1

Notes

SSO cookies not working in 5.0, have only been fixed in 5.5.13, see #34724
SSO cookies sent over secure connections do not require
secure connections, possibly defeating HTTPS encryption.
See: http://issues.apache.org/bugzilla/show_bug.cgi?id=41217

Search for package or bug name: Reporting problems