CVE-2007-5333

Apache Tomcat 4.1.0-4.1.35, 5.5.0-5.5.25, 6.0.0-6.0.14 - Session ID Exposure via Cookie Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5333. PoCs published by John Kew.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Apache Tomcat by manipulating cookie values to access sensitive data. It leverages improper sanitization of user-supplied input in cookie handling.

Description

Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.

Exploits (1)

exploitdb WORKING POC VERIFIED
by John Kew · textremotemultiple
https://www.exploit-db.com/exploits/31130

This exploit demonstrates an information disclosure vulnerability in Apache Tomcat by manipulating cookie values to access sensitive data. It leverages improper sanitization of user-supplied input in cookie handling.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat versions prior to 6.0.16 and 5.5.26
No auth needed
Prerequisites: Access to a vulnerable Apache Tomcat instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (55)

Core 55
Core References
URL Repurposed vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2690
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33330
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-4.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT2163
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30676
Broken Link third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3636
Exploit, Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27706
Third Party Advisory, VDB Entry third-party-advisory x_refsource_jvn
http://jvn.jp/jp/JVN%2309470767/index.html
URL Repurposed vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1981/references
Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20133
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28915
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37460
Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1IZ20991
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31681
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28884
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/487822/100/0/threaded
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27012048
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28878
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32036
URL Repurposed vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0488
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44183
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:176
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/507985/100/0/threaded
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2009:018
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-6.html
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57126
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32222
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30802
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27012047
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00315.html
Broken Link vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200804-10.xml
Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00460.html
URL Repurposed vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1856/references
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2008-0010.html
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-5.html
URL Repurposed vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2780
Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=139344343412337&w=2
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT3216
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg24018932
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29711
URL Repurposed vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3316
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=532111

Scores

EPSS 0.8753
EPSS Percentile 99.5%

Details

CWE
CWE-200
Status published
Products (2)
apache/tomcat 4.1.0 - 4.1.36
org.apache.tomcat/tomcat 6.0.0 - 6.0.15Maven
Published Feb 12, 2008
Tracked Since Feb 18, 2026