Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3190

Опубликовано: 31 авг. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

РелизСтатусПримечание
devel

DNE

hardy

released

5.5.25-5ubuntu1.3
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

released

5.5.34

Показывать по

РелизСтатусПримечание
devel

not-affected

6.0.32-5ubuntu1
hardy

DNE

lucid

released

6.0.24-2ubuntu1.9
maverick

released

6.0.28-2ubuntu1.5
natty

released

6.0.28-10ubuntu2.2
oneiric

not-affected

6.0.32-5ubuntu1
upstream

released

6.0.33

Показывать по

РелизСтатусПримечание
devel

released

7.0.21-1
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

released

7.0.21-1
upstream

released

7.0.21-1

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

nvd
около 14 лет назад

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

debian
около 14 лет назад

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 ...

github
больше 3 лет назад

Apache Tomcat Allows Remote Attackers to Spoof AJP Requests

oracle-oval
почти 14 лет назад

ELSA-2011-1780: tomcat6 security and bug fix update (MODERATE)

7.5 High

CVSS2