CVE-2017-5647

HIGH

Apache Tomcat < 9.0.0.M19 - Information Disclosure

Title source: rule
STIX 2.1

Description

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.

References (34)

Core 34
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201705-09
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180614-0001/
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3080
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1801
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3843
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2494
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038218
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3842
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1802
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:2493
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3081

Scores

CVSS v3 7.5
EPSS 0.0227
EPSS Percentile 84.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (50)
apache/tomcat 6.0.0
apache/tomcat 6.0.1
apache/tomcat 6.0.2
apache/tomcat 6.0.3
apache/tomcat 6.0.4
apache/tomcat 6.0.5
apache/tomcat 6.0.6
apache/tomcat 6.0.7
apache/tomcat 6.0.8
apache/tomcat 6.0.9
... and 40 more
Published Apr 17, 2017
Tracked Since Feb 18, 2026