First published: Thu Feb 26 2009(Updated: )
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tomcat | =5.5.18 | |
Apache Tomcat | =5.5.12 | |
Apache Tomcat | =5.5.14 | |
Apache Tomcat | =5.5.10 | |
Apache Tomcat | =5.5.11 | |
Apache Tomcat | =5.5.20 | |
Apache Tomcat | =5.5.15 | |
Apache Tomcat | =4.1.33 | |
Apache Tomcat | =5.5.13 | |
Apache Tomcat | =5.5.16 | |
Apache Tomcat | =5.5.17 | |
Apache Tomcat | =5.5.19 | |
Apache Tomcat | =4.1.34 | |
Apache Tomcat | =4.1.32 | |
maven/org.apache.tomcat:tomcat | >=5.5.10<5.5.21 | 5.5.21 |
maven/org.apache.tomcat:tomcat | >=4.1.32<4.1.35 | 4.1.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.