VDB
BDU%3A2020-01971
BDU%3A2020-01971
PUBLISHED
CVSS 10 CRITICAL
Уязвимость формы аутентификации сервера приложений Apache Tomcat, связанная с недостатком механизма фиксации сеанса, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании и оказать воздействие на целостность данных
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Canonical Ltd., Сообщество свободного программного обеспечения, Oracle Corp., Novell Inc., Apache Software Foundation, АО «Концерн ВНИИНС» | Red Hat Enterprise Linux, Ubuntu, Debian GNU/Linux, Oracle Transportation Management, Oracle Retail Order Broker, Instantis EnterpriseTrack, MICROS Relate CRM Software, Agile Engineering Data Management, OpenSUSE Leap, Database Server, Jboss Web Server, Tomcat, MySQL Enterprise Monitor, Hyperion Infrastructure Technology, ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- May 7, 2020 CVE Published
- Nov 21, 2023 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/CVE-2019-17563 url
- https://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html url
- https://usn.ubuntu.com/4251-1/ url
- https://lists.apache.org/thread.html/8b4c1db8300117b28a0f3f743c0b9e3f964687a690cdf9662a884bbd%40%3Cannounce.tomcat.apache.org%3E url
- https://nvd.nist.gov/vuln/detail/CVE-2019-17563 url
- https://security-tracker.debian.org/tracker/CVE-2019-17563 url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html url
- https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html url
- https://www.debian.org/security/2019/dsa-4596 url
- https://www.debian.org/security/2020/dsa-4680 url
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E advisory
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E advisory
- https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E advisory
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E advisory
- https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E advisory
- https://access.redhat.com/security/cve/cve-2019-17563 advisory
- https://www.suse.com/security/cve/CVE-2019-17563/ advisory
…and 1 more