The AJP connector in Apache Tomcat 4.0.1 up to and including 4.0.6 and 4.1.0 up to and including 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
hitachi cosminexus application server 05_00_05_05_e |
||
hitachi cosminexus application server 05_00_05_05_h |
||
hitachi cosminexus application server 05_00_05_05_k |
||
hitachi cosminexus application server 05_00_05_05_f |
||
apache tomcat |