Loading...
Loading...
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
August 14, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-3385
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.