CVE-2013-2067EPSS p94.1%

CVE-2013-2067CVE-2013-2067

apache / tomcat

Description

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

Scoring

CVSS 6.8 ()
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS7.15% probability of exploitation · percentile 94.1% · 2026-10-10T12:00:23Z
Last modified2026-10-09
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.