vulnerability
Apache Tomcat: Important: Information Disclosure (CVE-2016-8745)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Dec 13, 2016 | Dec 13, 2016 | May 5, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Dec 13, 2016
Added
Dec 13, 2016
Modified
May 5, 2025
Description
A bug in the error handling of the send file code for the NIO HTTP
connector resulted in the current Processor object being added to the
Processor cache multiple times. This in turn meant that the same
Processor could be used for concurrent requests. Sharing a Processor can
result in information leakage between requests including, but not limited
to, session ID and the response body.
Solutions
apache-tomcat-upgrade-6_0_50apache-tomcat-upgrade-7_0_75apache-tomcat-upgrade-8_0_41apache-tomcat-upgrade-8_5_9
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.