CVE-2007-3382

Apache Tomcat Session ID Exposure via Cookie Delimiter Mishandling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3382. PoCs published by Tomasz Kuczynski.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Apache Tomcat by manipulating cookie values to inject arbitrary data. The vulnerability arises from inadequate sanitization of user-supplied input in the CookieExample servlet.

Description

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Tomasz Kuczynski · textremotemultiple
https://www.exploit-db.com/exploits/30496

This exploit demonstrates an information disclosure vulnerability in Apache Tomcat by manipulating cookie values to inject arbitrary data. The vulnerability arises from inadequate sanitization of user-supplied input in the CookieExample servlet.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat versions prior to 6.0.14
No auth needed
Prerequisites: Access to the target Tomcat server with the vulnerable servlet exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (46)

Core 46
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0261.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11269
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36006
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1453
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0950.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2163
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/476466/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1981/references
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27267
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29242
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3527
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018556
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26466
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500412/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33668
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2902
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/500396/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26898
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28361
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ55562
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28317
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0233
Patch x_refsource_confirm
http://tomcat.apache.org/security-6.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0871.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3386
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30802
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0195.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27037
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25316
Patch, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/993544
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27727
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/476442/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36486
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1447
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:241

Scores

EPSS 0.8141
EPSS Percentile 99.2%

Details

CWE
CWE-200
Status published
Products (49)
apache/tomcat 3.3
apache/tomcat 3.3.1
apache/tomcat 3.3.1a
apache/tomcat 3.3.2
apache/tomcat 4.1.0
apache/tomcat 4.1.1
apache/tomcat 4.1.2
apache/tomcat 4.1.3 (2 CPE variants)
apache/tomcat 4.1.9 beta
apache/tomcat 4.1.10
... and 39 more
Published Aug 14, 2007
Tracked Since Feb 18, 2026