5
CVSSv2

CVE-2011-1475

Published: 08/04/2011 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The HTTP BIO connector in Apache Tomcat 7.0.x prior to 7.0.12 does not properly handle HTTP pipelining, which allows remote malicious users to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."

Affected Products

Vendor Product Versions
ApacheTomcat7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11

Github Repositories

CVE-2011-1475 Check dependency vulnerabilities using Maven on CVE-2011-1475 This project is to test Maven with Travis CI

CVE-2011-1475 Check dependency vulnerabilities using Maven on CVE-2011-1475 This project is to test Maven with Travis CI