CVE-2005-3164
published 2005-10-06CVE-2005-3164: The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not…
PriorityP417low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
6.52%
93.1th percentile
The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | 4.0.1 – 4.0.6 | — |
| apache | tomcat | 4.1.0 – 4.1.36 | — |
| hitachi | cosminexus_application_server | — | — |
| hitachi | cosminexus_application_server | — | — |
| hitachi | cosminexus_application_server | — | — |
| hitachi | cosminexus_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Tomcat AJP Connector Information Leak
osv·2022-05-01
CVE-2005-3164 [LOW] Apache Tomcat AJP Connector Information Leak
Apache Tomcat AJP Connector Information Leak
The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
GHSA
Apache Tomcat AJP Connector Information Leak
ghsa·2022-05-01
CVE-2005-3164 [LOW] CWE-200 Apache Tomcat AJP Connector Information Leak
Apache Tomcat AJP Connector Information Leak
The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
No detection rules found.
No public exploits indexed.
http://jvn.jp/jp/JVN%2379314822/index.htmlhttp://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlhttp://secunia.com/advisories/17019http://secunia.com/advisories/30802http://secunia.com/advisories/30899http://secunia.com/advisories/30908http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1http://support.apple.com/kb/HT2163http://tomcat.apache.org/security-4.htmlhttp://www.hitachi-support.com/security_e/vuls_e/HS05-019_e/01-e.htmlhttp://www.securityfocus.com/bid/15003http://www.vupen.com/english/advisories/2008/1979/referenceshttp://www.vupen.com/english/advisories/2008/1981/referenceshttps://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3Ehttp://jvn.jp/jp/JVN%2379314822/index.htmlhttp://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlhttp://secunia.com/advisories/17019http://secunia.com/advisories/30802http://secunia.com/advisories/30899http://secunia.com/advisories/30908http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1http://support.apple.com/kb/HT2163http://tomcat.apache.org/security-4.htmlhttp://www.hitachi-support.com/security_e/vuls_e/HS05-019_e/01-e.htmlhttp://www.securityfocus.com/bid/15003http://www.vupen.com/english/advisories/2008/1979/referenceshttp://www.vupen.com/english/advisories/2008/1981/referenceshttps://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
2005-10-06
Published