Apache Tomcat's default configuration does not include the 'HTTPOnly' flag in a 'Set-Cookie' header. The issue allows remote attackers to more easily hijack a session via script access to a cookie.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 7.0.5 or 6.0.30 or higher upon their release, as they have been reported to fix this vulnerability. In addition, Apache has released a patch for versions 7.0.4 and 6.0.29 to mitigate the issue.