Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 4.1.32Upgrade Apache Tomcat to 5.5.1Upgrade Apache Tomcat to the latest available version | May 17, 2012 | Oct 13, 2008 |
| Suse | — | Upgrade jakarta-tomcat-examplesUpgrade apache-jakarta-tomcat-connectorsUpgrade jakarta-tomcat-docUpgrade tomcat5-admin-webappsUpgrade tomcat5-webappsUpgrade jakarta-tomcatUpgrade suse-releaseUpgrade apache2-jakarta-tomcat-connectorsUpgrade tomcat5 | Feb 17, 2015 | Oct 13, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub