CVE-2005-3164

Apache Tomcat 4.0.1-4.0.6/4.1.0-4.1.36 - Info Disclosure

Title source: llm
STIX 2.1

Description

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

References (16)

Core 16
Core References
Vendor Advisory x_refsource_confirm
http://tomcat.apache.org/security-4.html
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30908
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT2163
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15003
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1981/references
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30899
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1979/references
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17019
Mailing List, Third Party Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30802
VDB Entry third-party-advisory x_refsource_jvn
http://jvn.jp/jp/JVN%2379314822/index.html

Scores

EPSS 0.0339
EPSS Percentile 87.6%

Details

CWE
CWE-200
Status published
Products (6)
apache/tomcat 4.0.1 - 4.0.6
hitachi/cosminexus_application_server 05_00_05_05_e
hitachi/cosminexus_application_server 05_00_05_05_f
hitachi/cosminexus_application_server 05_00_05_05_h
hitachi/cosminexus_application_server 05_00_05_05_k
org.apache.tomcat/tomcat 4.0.1Maven
Published Oct 06, 2005
Tracked Since Feb 18, 2026