Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37388
HistoryOct 03, 2022 - 8:39 a.m.

Information Disclosure

2022-10-0308:39:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
apache tomcat-coyote
vulnerability
information disclosure
remote attacker
http11processor
blocking reads
sensitive information

EPSS

0.002

Percentile

58.5%

Apache Tomcat-Coyote is vulnerable to information disclosure. A remote unauthenticated attacker is able to cause client connections to share an Http11Processor instance resulting in responses or part responses to be received by a malicious client due to the simplified implementation of blocking reads and writes, disclosing sensitive information.