In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could result in the same Processor being used for multiple requests which in turn could lead to unexpected errors and/or response mix-up.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 9.0.0Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 8.5.13 | Apr 17, 2017 | Apr 17, 2017 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Apr 17, 2017 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat-8 to version 8.5.13-0.175.3.21.0.1.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.13-0.175.3.21.0.1.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.13-0.175.3.21.0.1.0 on Solaris 11.3 | Jun 20, 2017 | Apr 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub