CVE-2008-4308 — Sensitive Information Exposure in Apache Tomcat
Severity
2.6LOWNVD
EPSS
7.6%
top 8.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 26
Latest updateMay 2
Description
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
CVSS vector
AV:N/AC:H/C:P/I:N/A:NExploitability: 4.9 | Impact: 2.9