Description
The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
Remediation
References
Related Vulnerabilities
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0702)
WordPress Plugin Broken Link Manager Cross-Site Scripting (0.5.5)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-3722)
WordPress Plugin WP-Forum Multiple SQL Injection Vulnerabilities (2.3)