Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2071
HistoryMay 10, 2013 - 12:00 a.m.

CVE-2013-2071

2013-05-1000:00:00
ubuntu.com
ubuntu.com
17

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

58.7%

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x
before 7.0.40 does not properly handle the throwing of a RuntimeException
in an AsyncListener in an application, which allows context-dependent
attackers to obtain sensitive request information intended for other
applications in opportunistic circumstances via an application that records
the requests that it processes.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu12.10noarchtomcat7< 7.0.30-0ubuntu1.2UNKNOWN
ubuntu13.04noarchtomcat7< 7.0.35-1~exp2ubuntu1.1UNKNOWN

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

58.7%