VDB
RHSA-2016%3A2808
RHSA-2016%3A2808
PUBLISHED
CVSS 8.100000381469727 HIGH
A session fixation flaw was found in the way Tomcat recycled the requestedSessionSSL field. If at least one web application was configured to use the SSL session ID as the HTTP session ID, an attacker could reuse a previously used session ID for further requests.
Risk Scores
CVSS 3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 2.1 |
Timeline
- Nov 17, 2016 CVE Published
- Mar 4, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2016:2808 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=distributions&version=2.1.2 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1311076 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1311082 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1311085 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1311087 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1311093 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1349468 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2016/rhsa-2016_2808.json advisory
- https://access.redhat.com/security/cve/CVE-2015-5346 advisory
- https://www.cve.org/CVERecord?id=CVE-2015-5346 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-5346 advisory
- http://seclists.org/bugtraq/2016/Feb/143 advisory
- https://access.redhat.com/security/cve/CVE-2015-5351 advisory
- https://www.cve.org/CVERecord?id=CVE-2015-5351 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-5351 advisory
- http://seclists.org/bugtraq/2016/Feb/148 advisory
- https://access.redhat.com/security/cve/CVE-2016-0706 advisory
- https://www.cve.org/CVERecord?id=CVE-2016-0706 advisory
…and 15 more