AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-3385

MEDIUM · CVSS 4.3 EPSS 16.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-08-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-3385
Severity
MEDIUM
CVSS
4.3
EPSS
16.94%
Apache

Original NVD Description

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.