Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3190

Опубликовано: 31 авг. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

РелизСтатусПримечание
devel

DNE

hardy

released

5.5.25-5ubuntu1.3
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

released

5.5.34

Показывать по

РелизСтатусПримечание
devel

not-affected

6.0.32-5ubuntu1
hardy

DNE

lucid

released

6.0.24-2ubuntu1.9
maverick

released

6.0.28-2ubuntu1.5
natty

released

6.0.28-10ubuntu2.2
oneiric

not-affected

6.0.32-5ubuntu1
upstream

released

6.0.33

Показывать по

РелизСтатусПримечание
devel

released

7.0.21-1
hardy

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

released

7.0.21-1
upstream

released

7.0.21-1

Показывать по

EPSS

Процентиль: 74%
0.00872
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 14 лет назад

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

nvd
почти 14 лет назад

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

debian
почти 14 лет назад

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 ...

github
около 3 лет назад

Apache Tomcat Allows Remote Attackers to Spoof AJP Requests

oracle-oval
больше 13 лет назад

ELSA-2011-1780: tomcat6 security and bug fix update (MODERATE)

EPSS

Процентиль: 74%
0.00872
Низкий

7.5 High

CVSS2