CVE-2017-5647Sensitive Information Exposure in Software Foundation Apache Tomcat

Severity
7.5HIGHNVD
EPSS
2.3%
top 15.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 14

Description

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C fo

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/tomcat187 versions+186

🔴Vulnerability Details

5
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat2022-05-14
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat2022-05-14
OSV
tomcat7, tomcat8 vulnerabilities2018-01-08
CVEList
CVE-2017-5647: A bug in the handling of the pipelined requests in Apache Tomcat 92017-04-17
OSV
CVE-2017-5647: A bug in the handling of the pipelined requests in Apache Tomcat 92017-04-17

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2018-01-08
Red Hat
tomcat: Incorrect handling of pipelined requests when send file was used2017-04-10
Debian
CVE-2017-5647: tomcat9 - A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0...2017
Apache
Apache tomcat: CVE-2017-5647

💬Community

3
Bugzilla
CVE-2017-5647 CVE-2017-5648 tomcat: various flaws [epel-6]2017-04-11
Bugzilla
CVE-2017-5647 tomcat: Incorrect handling of pipelined requests when send file was used2017-04-11
Bugzilla
CVE-2017-5647 CVE-2017-5648 tomcat: various flaws [fedora-all]2017-04-11
CVE-2017-5647 — Sensitive Information Exposure | cvebase