PT-2016-7560 · Apache+5 · Apache Tomcat+5

Publicado

2016-12-08

·

Atualizado

2024-06-15

·

CVE-2016-8745

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.0.M1 through 9.0.0.M13 Apache Tomcat versions 8.5.0 through 8.5.8 Apache Tomcat versions 8.0.0.RC1 through 8.0.39 Apache Tomcat versions 7.0.0 through 7.0.73 Apache Tomcat versions 6.0.16 through 6.0.48
Description A bug in the error handling of the send file code for the NIO HTTP connector resulted in the current Processor object being added to the Processor cache multiple times. This allowed the same Processor to be used for concurrent requests, potentially leading to information leakage between requests, including session ID and the response body.
Recommendations For Apache Tomcat versions 9.0.0.M1 through 9.0.0.M13, update to a version outside of this range to mitigate the risk. For Apache Tomcat versions 8.5.0 through 8.5.8, update to a version outside of this range to mitigate the risk. For Apache Tomcat versions 8.0.0.RC1 through 8.0.39, update to a version outside of this range to mitigate the risk. For Apache Tomcat versions 7.0.0 through 7.0.73, update to a version outside of this range to mitigate the risk. For Apache Tomcat versions 6.0.16 through 6.0.48, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider disabling the NIO HTTP connector until a patch is available.

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2558
CESA-2017_0527
CESA-2017_0935
CVE-2016-8745
DLA-779-1
DSA-3754-1
DSA-3755-1
GHSA-W3J5-Q8F2-3CQQ
MGASA-2017-0050
OPENSUSE-SU-2017_1292-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2017:0455
RHSA-2017:0456
RHSA-2017:0527
RHSA-2017:0935
RHSA-2017_0527
RHSA-2017_0935
SUSE-SU-2017:1229-1
SUSE-SU-2017:1382-1
SUSE-SU-2017:1632-1
SUSE-SU-2017:1660-1
SUSE-SU-2017_1229-1
SUSE-SU-2017_1382-1
USN-3177-1
USN-3177-2

Produtos afetados

Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu