CVE-2011-1475: Input Validation
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1475?
CVE-2011-1475 has a medium severity rating allowing attackers to potentially read responses meant for other clients.
Which versions of Apache Tomcat are affected by CVE-2011-1475?
CVE-2011-1475 affects Apache Tomcat versions from 7.0.0 to 7.0.11.
How do I fix CVE-2011-1475?
To fix CVE-2011-1475, upgrade Apache Tomcat to version 7.0.12 or later.
What kind of attack can exploit CVE-2011-1475?
CVE-2011-1475 can be exploited by attackers using HTTP pipelining to read other clients' responses.
Is there a workaround for CVE-2011-1475?
There are no specific workarounds for CVE-2011-1475; upgrading to the patched version is recommended.