Lucene search

K
cve[email protected]CVE-2006-7197
HistoryApr 25, 2007 - 8:19 p.m.

CVE-2006-7197

2007-04-2520:19:00
web.nvd.nist.gov
37
cve
2006
7197
apache tomcat
ajp connector
vulnerability
remote attacks
memory read
nvd

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

9.3 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.0%

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

Affected configurations

NVD
Node
apachetomcatMatch5.5.15
CPENameOperatorVersion
apache:tomcatapache tomcateq5.5.15

References

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

9.3 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.0%