CVE-2013-4286

Related Vulnerabilities: CVE-2013-4286  

It was found that when Tomcat / JBoss Web processed a series of HTTP requests in which at least one request contained either multiple content-length headers, or one content-length header with a chunked transfer-encoding header, Tomcat / JBoss Web would incorrectly handle the request. A remote attacker could use this flaw to poison a web cache, perform cross-site scripting (XSS) attacks, or obtain sensitive information from other requests.

It was found that when Tomcat / JBoss Web processed a series of HTTP requests in which at least one request contained either multiple content-length headers, or one content-length header with a chunked transfer-encoding header, Tomcat / JBoss Web would incorrectly handle the request. A remote attacker could use this flaw to poison a web cache, perform cross-site scripting (XSS) attacks, or obtain sensitive information from other requests.

Find out more about CVE-2013-4286 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 5.8
Base Metrics AV:N/AC:M/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 Server (tomcat7) RHSA-2014:0526 2014-05-21
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 Server (tomcat6) RHSA-2014:0525 2014-05-21
Red Hat Enterprise Linux 6 (tomcat6) RHSA-2014:0429 2014-04-23
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server (jbossweb) RHSA-2014:0343 2014-03-31
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (jbossweb) RHSA-2014:0344 2014-03-31
Red Hat Enterprise Linux 7 (tomcat) RHSA-2014:0686 2014-06-10
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 Server (tomcat7) RHSA-2014:0526 2014-05-21
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 Server (tomcat6) RHSA-2014:0525 2014-05-21

Affected Packages State

Platform Package State
Red Hat JBoss Portal Platform 6 jbossweb Will not fix
Red Hat JBoss Operations Network 3 jbossweb Will not fix
Red Hat JBoss Fuse Service Works 6 jbossweb Will not fix
Red Hat JBoss EWS 1 tomcat6 Will not fix
Red Hat JBoss EWS 1 tomcat5 Will not fix
Red Hat JBoss EAP 5 jbossweb Will not fix
Red Hat JBoss Data Virtualization 6 jbossweb Will not fix
Red Hat JBoss Data Grid 6 jbossweb Will not fix
Red Hat JBoss BRMS 6 jbossweb Will not fix
Red Hat JBoss BPMS 6 jbossweb Will not fix
Red Hat Enterprise Linux 5 tomcat5 Will not fix