
We found results for “”
CVE-2025-55668
Good to know:


Date: August 13, 2025
Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected.
Severity Score
Related Resources (12)
Severity Score
Weakness Type (CWE)
Session Fixation
CWE-384Top Fix

Upgrade Version
Upgrade to version org.apache.tomcat:tomcat-catalina:9.0.106;org.apache.tomcat:tomcat-catalina:10.1.42;org.apache.tomcat:tomcat-catalina:11.0.8;org.apache.tomcat.embed:tomcat-embed-core:9.0.106;org.apache.tomcat.embed:tomcat-embed-core:10.1.42;org.apache.tomcat.embed:tomcat-embed-core:11.0.8;https://github.com/apache/tomcat.git - 9.0.106;https://github.com/apache/tomcat.git - 10.1.42;https://github.com/apache/tomcat.git - 11.0.8
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |