vulnerability

Apache Tomcat: Important: Information Disclosure (CVE-2016-8745)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Dec 13, 2016
Added
Dec 13, 2016
Modified
May 5, 2025

Description

A bug in the error handling of the send file code for the NIO HTTP
connector resulted in the current Processor object being added to the
Processor cache multiple times. This in turn meant that the same
Processor could be used for concurrent requests. Sharing a Processor can
result in information leakage between requests including, but not limited
to, session ID and the response body.

Solutions

apache-tomcat-upgrade-6_0_50apache-tomcat-upgrade-7_0_75apache-tomcat-upgrade-8_0_41apache-tomcat-upgrade-8_5_9
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.