<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 00:18:56 +0000</lastBuildDate>
    <item>
      <title>certa-2013-avi-334 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Apache Tomcat&lt;/span&gt;. Elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certa-2013-avi-334</link>
      <description>certa-2013-avi-334</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certa-2013-avi-334</guid>
    </item>
    <item>
      <title>EUVD-2026-105890</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-105890</link>
      <description>EUVD-2026-105890</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-105890</guid>
    </item>
    <item>
      <title>fkie_cve-2013-2067</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2013-2067</link>
      <description>&lt;p&gt;java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2013-2067</guid>
    </item>
    <item>
      <title>GHSA-6m48-jxwx-76q7 — Improper Authentication in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6m48-jxwx-76q7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat&lt;/p&gt;
&lt;p&gt;java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6m48-jxwx-76q7</guid>
    </item>
    <item>
      <title>gsd-2013-2067</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2013-2067</link>
      <description>gsd-2013-2067</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2013-2067</guid>
    </item>
    <item>
      <title>RHSA-2013:0833 — Red Hat Security Advisory: JBoss Enterprise Application Platform 6.1.0 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2013:0833</link>
      <description>&lt;p&gt;Web: jsessionid exposed via encoded url when using cookie based session tracking JBoss: custom authorization module implementations shared between applications apache-cxf: XML encryption backwards compatibility attacks openssl: DoS due to improper handling of OCSP response verification SSL/TLS: CBC padding timing attack (lucky-13) Installer: Generated auto-install xml is world readable tomcat: Session fixation in form authenticator&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Web: jsessionid exposed via encoded url when using cookie based session tracking JBoss: custom authorization module implementations shared between applications apache-cxf: XML encryption backwards compatibility attacks openssl: DoS due to improper handling of OCSP response verification SSL/TLS: CBC padding timing attack (lucky-13) Installer: Generated auto-install xml is world readable tomcat: Session fixation in form authenticator&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2013:0833</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2013-2067</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-2067</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: tomcat6&lt;/p&gt;
&lt;p&gt;java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2013-2067</guid>
    </item>
  </channel>
</rss>
