Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
BID:49470
Info
Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
| Bugtraq ID: | 49470 |
| Class: | Design Error |
| CVE: |
CVE-2007-6286 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2008 12:00AM |
| Updated: | Apr 13 2015 10:12PM |
| Credit: | System Core |
| Vulnerable: |
VMWare VirtualCenter 2.0.2 VMWare VirtualCenter 2.5 VMWare vCenter 4.0 VMWare Server 2.0.2 VMWare Server 2.0.1 VMWare Server 2.0 VMWare ESX Server 3.0.3 VMWare ESX Server 4.0 VMWare ESX Server 3.5 VMWare ESX 4.0 VMWare ESX 3.5 SuSE SUSE Linux Enterprise Server 10 SP2 Sun Solaris 10 Redhat Fedora 7 HP XP P9000 Performance Advisor 5.4.1 Apple Mac OS X Server 10.5.5 Apache Tomcat 6.0.15 Apache Tomcat 6.0.14 Apache Tomcat 6.0.13 Apache Tomcat 6.0.12 Apache Tomcat 6.0.11 Apache Tomcat 6.0.10 Apache Tomcat 6.0.9 Apache Tomcat 6.0.8 Apache Tomcat 6.0.7 Apache Tomcat 6.0.6 Apache Tomcat 6.0.5 Apache Tomcat 6.0.4 Apache Tomcat 6.0.3 Apache Tomcat 6.0.2 Apache Tomcat 6.0.1 Apache Tomcat 6.0 Apache Tomcat 5.5.25 Apache Tomcat 5.5.24 Apache Tomcat 5.5.23 Apache Tomcat 5.5.22 Apache Tomcat 5.5.21 Apache Tomcat 5.5.20 Apache Tomcat 5.5.19 Apache Tomcat 5.5.18 Apache Tomcat 5.5.17 Apache Tomcat 5.5.16 Apache Tomcat 5.5.15 Apache Tomcat 5.5.14 Apache Tomcat 5.5.13 Apache Tomcat 5.5.12 Apache Tomcat 5.5.11 Apache Tomcat 5.5.9 Apache Tomcat 5.5.8 Apache Tomcat 5.5.7 Apache Tomcat 5.5.6 Apache Tomcat 5.5.5 |
| Not Vulnerable: |
VMWare VirtualCenter 2.5 Update 6 VMWare vCenter 4.0 Update 1 HP XP P9000 Performance Advisor 5.5.1 Apache Tomcat 6.0.16 Apache Tomcat 5.5.26 |
Discussion
Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
Apache Tomcat is prone to a security vulnerability that will compromise data integrity when the native APR connector is used.
Successful exploits will allow attackers to trigger handling of a duplicate copy of one of the recent requests
received by the vulnerable server.
Apache Tomcat 5.5.11 to 5.5.25 and 6.0.0 to 6.0.15 are vulnerable.
Apache Tomcat is prone to a security vulnerability that will compromise data integrity when the native APR connector is used.
Successful exploits will allow attackers to trigger handling of a duplicate copy of one of the recent requests
received by the vulnerable server.
Apache Tomcat 5.5.11 to 5.5.25 and 6.0.0 to 6.0.15 are vulnerable.
Exploit / POC
Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
Attackers can use standard tools to exploit this issue.
Attackers can use standard tools to exploit this issue.
Solution / Fix
Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache Tomcat CVE-2007-6286 Duplicate Request Processing Security Vulnerability
References:
References:
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat 6.x vulnerabilities (Apache)
- Apache Tomcat Homepage (Apache)
- Multiple vulnerabilities in Oracle Java Web Console (Oracle)
- Multiple vulnerabilities in Oracle Java Web Console1 (Oracle)
- [security-announce] SUSE Security Summary Report: SUSE-SR:2009:004 (SUSE)
- [SECURITY] CVE-2007-6286: Tomcat duplicate request processing vulnerability (Mark Thomas)
- HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software (HP)