CVE-2014-0033 | Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37 coyoteadapter.java disableURLRewriting Session Hijacking input validation (Revision 1149220 / Nessus ID 72690)
A vulnerability classified as critical has been found in Apache Tomcat 6.0.33/6.0.34/6.0.35/6.0.36/6.0.37. Affected is the function disableURLRewriting of the file org/apache/catalina/connector/coyoteadapter.java. The manipulation leads to improper input validation (Session Hijacking).
This vulnerability is traded as CVE-2014-0033. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.