PT-2017-9778 · Apache · Apache Tomcat
Published
2017-01-16
·
Updated
2024-10-15
·
CVE-2016-8747
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 8.5.7 through 8.5.9
Apache Tomcat versions 9.0.0.M11 through 9.0.0.M15
Description
An information disclosure issue was discovered in Apache Tomcat in reverse-proxy configurations, allowing remote attackers to read data intended for a different request. The issue is caused by a regression introduced by the refactoring to make wider use of ByteBuffer, which could cause information to leak between requests on the same connection. All HTTP connector variants are affected.
Recommendations
For Apache Tomcat versions 8.5.7 through 8.5.9, update to a version outside of this range to resolve the issue.
For Apache Tomcat versions 9.0.0.M11 through 9.0.0.M15, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting the use of HTTP connector variants to minimize the risk of information leakage between users.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat