CVE-2011-1475
published 2011-04-08CVE-2011-1475: The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
8.69%
94.6th percentile
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: Information disclosure due improper handling of HTTP pipelining
vendor_redhat·2011-04-06·CVSS 5.0
CVE-2011-1475 [MEDIUM] tomcat: Information disclosure due improper handling of HTTP pipelining
tomcat: Information disclosure due improper handling of HTTP pipelining
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
Statement: Not vulnerable. This issue did not affect the versions of Apache Tomcat 5 as shipped with Red Hat Enterprise Linux 5, Red Hat Developer Suite 3, Red Hat Certificate System 7.3, Red Hat Network Satellite 5.3.0 and earlier versions and JBoss Enterprise Web Server 1.0. It did not affect the versions of Apache Tomcat 6 as shipped with Red Hat Enterprise Linux 6 and JBoss Enterprise Web S
OSV
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
osv·2022-05-17
CVE-2011-1475 [MEDIUM] Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
GHSA
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
ghsa·2022-05-17
CVE-2011-1475 [MEDIUM] CWE-20 Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2011/Apr/97http://securityreason.com/securityalert/8188http://svn.apache.org/viewvc?view=revision&revision=1086349http://svn.apache.org/viewvc?view=revision&revision=1086352http://tomcat.apache.org/security-7.htmlhttp://www.securityfocus.com/archive/1/517363http://www.securityfocus.com/bid/47199http://www.securitytracker.com/id?1025303http://www.vupen.com/english/advisories/2011/0894https://exchange.xforce.ibmcloud.com/vulnerabilities/66676https://issues.apache.org/bugzilla/show_bug.cgi?id=50957https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12374http://seclists.org/fulldisclosure/2011/Apr/97http://securityreason.com/securityalert/8188http://svn.apache.org/viewvc?view=revision&revision=1086349http://svn.apache.org/viewvc?view=revision&revision=1086352http://tomcat.apache.org/security-7.htmlhttp://www.securityfocus.com/archive/1/517363http://www.securityfocus.com/bid/47199http://www.securitytracker.com/id?1025303http://www.vupen.com/english/advisories/2011/0894https://exchange.xforce.ibmcloud.com/vulnerabilities/66676https://issues.apache.org/bugzilla/show_bug.cgi?id=50957https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12374
2011-04-08
Published