java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 7.0.40 | Jun 1, 2013 | Jun 1, 2013 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Jun 1, 2013 |
| Suse | — | Upgrade tomcat-jsp-2_2-apiUpgrade tomcat-docs-webappUpgrade tomcat-javadocUpgrade tomcat-el-2_2-apiUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-3_0-apiUpgrade tomcatUpgrade tomcat-jsvcUpgrade tomcat-libUpgrade tomcat-webapps | Dec 12, 2013 | Jun 1, 2013 |
| Ubuntu | — | Upgrade libtomcat6-javaUpgrade libtomcat7-java | Nov 8, 2024 | Jun 1, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub