Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 4.1.32Upgrade Apache Tomcat to 5.5.1 | May 17, 2012 | Oct 13, 2008 |
| Suse | — | Upgrade jakarta-tomcat-examplesUpgrade apache-jakarta-tomcat-connectorsUpgrade tomcat5Upgrade jakarta-tomcat-docUpgrade jakarta-tomcatUpgrade tomcat5-webappsUpgrade apache2-jakarta-tomcat-connectorsUpgrade tomcat5-admin-webappsUpgrade suse-release | Feb 17, 2015 | Oct 13, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub