Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2077-1 | tomcat7 security update |
Debian DLA |
DLA-2209-1 | tomcat8 security update |
Debian DSA |
DSA-4596-1 | tomcat8 security update |
Debian DSA |
DSA-4680-1 | tomcat9 security update |
EUVD |
EUVD-2019-0787 | When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. |
Github GHSA |
GHSA-9xcj-c8cr-8c3c | In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack |
Ubuntu USN |
USN-4251-1 | Tomcat vulnerabilities |
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-08T21:03:21.902Z
Reserved: 2019-10-14T00:00:00.000Z
Link: CVE-2019-17563
Updated: 2024-08-05T01:40:15.805Z
Status : Modified
Published: 2019-12-23T17:15:11.803
Modified: 2026-10-08T21:17:17.253
Link: CVE-2019-17563
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN