vulnerability

Apache Tomcat: Important: Information Disclosure (CVE-2016-8745)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
2016-12-13
Added
2016-12-13
Modified
2025-05-05

Description

A bug in the error handling of the send file code for the NIO HTTP
connector resulted in the current Processor object being added to the
Processor cache multiple times. This in turn meant that the same
Processor could be used for concurrent requests. Sharing a Processor can
result in information leakage between requests including, but not limited
to, session ID and the response body.

Solution(s)

apache-tomcat-upgrade-6_0_50apache-tomcat-upgrade-7_0_75apache-tomcat-upgrade-8_0_41apache-tomcat-upgrade-8_5_9
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.