Severity
9.8CRITICAL
EPSS
29.5%
top 3.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 12
Latest updateMay 14

Description

Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-jf5p-rxcp-5pm7: Buffer overflow in Apache Tomcat Connectors (mod_jk) before 12022-05-14
CVEList
CVE-2016-6808: Buffer overflow in Apache Tomcat Connectors (mod_jk) before 12017-04-12

📋Vendor Advisories

2
Red Hat
mod_jk: Buffer overflow when concatenating virtual host name and URI2016-10-06
Debian
CVE-2016-6808: libapache-mod-jk - Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.2016

💬Community

1
Bugzilla
CVE-2016-6808 mod_jk: Buffer overflow when concatenating virtual host name and URI2016-10-06
CVE-2016-6808 (CRITICAL CVSS 9.8) | Buffer overflow in Apache Tomcat Co | cvebase.io