Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ruediger Pluem

#33184of 53,632
7.8Total CVSS
Vulnerabilities · 1
PT-2007-1473
7.8
2007-04-25
Apache · Apache Tomcat · CVE-2006-7197
**Name of the Vulnerable Software and Affected Versions** Apache Tomcat version 5.5.15 **Description** The issue is related to the AJP connector in Apache Tomcat, which uses an incorrect length for chunks. This can cause a buffer over-read in the `ajp process callback` function in mod jk, allowing remote attackers to read portions of sensitive memory. **Recommendations** For Apache Tomcat version 5.5.15, consider disabling the AJP connector as a temporary workaround until a patch is available. Restrict access to the mod jk module to minimize the risk of exploitation.