>> Apache Tomcat SingleSignOn Cookie Information Disclosure Weakness
Title : Apache Tomcat SingleSignOn Cookie Information Disclosure Weakness VUPEN ID : VUPEN/ADV-2008-0192 CVE ID : CVE-2008-0128
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-01-21
Technical Description
A weakness has been identified in Apache Tomcat, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused due to the JSESSIONIDSSO cookie being sent without the "secure" attribute when using the SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) over HTTPS, which could be exploited to disclose sensitive information.