Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
BID:47199
Info
Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
| Bugtraq ID: | 47199 |
| Class: | Design Error |
| CVE: |
CVE-2011-1475 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 06 2011 12:00AM |
| Updated: | Mar 19 2015 08:33AM |
| Credit: | Brad Piles |
| Vulnerable: |
Gentoo Linux Apache Tomcat 7.0.1 Apache Tomcat 7.0 beta Apache Tomcat 7.0 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 |
| Not Vulnerable: |
Apache Tomcat 7.0.12 |
Discussion
Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
Apache Tomcat is prone to an information-disclosure vulnerability. The issue occurs in the HTTP BIO connector.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
Apache Tomcat 7.0.0 to 7.0.11 are vulnerable; other versions may also be affected.
Apache Tomcat is prone to an information-disclosure vulnerability. The issue occurs in the HTTP BIO connector.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
Apache Tomcat 7.0.0 to 7.0.11 are vulnerable; other versions may also be affected.
Exploit / POC
Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more details.
Apache Tomcat 7.0.11
Solution:
Updates are available. Please see the references for more details.
Apache Tomcat 7.0.11
-
Apache Software Foundation apache-tomcat-7.0.12.zip
http://apache.mirror.iweb.ca/tomcat/tomcat-7/v7.0.12/binhttp://apache. mirror.iweb.ca/tomcat/tomcat-7/v7.0.12/bin/apache-tomcat-7.0.12.zip
References
Apache Tomcat HTTP BIO Connector Information Disclosure Vulnerability
References:
References:
- [SECURITY] CVE-2011-1475 Apache Tomcat information disclosure (Apache Software Foundation)
- Apache Tomcat Homepage (Apache)
- CVE-2011-1475 Apache Tomcat information disclosure (Mark Thomas
)