-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.tomcat:tomcat | maven | = 9.0.0.M1 | 9.0.0.M2 |
| org.apache.tomcat:tomcat | maven | >= 8.0.0.RC1, <= 8.0.30 | 8.0.31 |
| org.apache.tomcat:tomcat | maven | >= 7.0.0, <= 7.0.65 | 7.0.66 |
The analysis involved examining the patches for CVE-2015-5346 across different versions of Apache Tomcat. The vulnerable functions were identified based on the changes made to handle session information and cookie recycling properly. The functions directly related to the vulnerability are those involved in the recycling of request and session information.