QID 995517
Date Published: 2023-10-09
QID 995517: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-qrj4-rmqg-4hcp)
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qrj4-rmqg-4hcp for updates and patch information.
Vendor References
- GHSA-qrj4-rmqg-4hcp -
github.com/advisories/GHSA-qrj4-rmqg-4hcp
CVEs related to QID 995517
Software Advisories
| Advisory ID | Software | Component | Link |
|---|