Lucene search

K
f5F5F5:K49000195
HistoryMay 05, 2017 - 12:00 a.m.

K49000195 : Apache Tomcat vulnerability CVE-2017-5647

2017-05-0500:00:00
my.f5.com
21

AI Score

8.2

Confidence

High

EPSS

0.003

Percentile

68.7%

Security Advisory Description

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C. (CVE-2017-5647)
Impact
This vulnerability allows unauthorized disclosure of information.