First published: Wed Feb 19 2025(Updated: )
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Traffix Systems Signaling Delivery Controller | =5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000149857 is considered high due to the potential for request and response mix-ups between users.
To fix F5-K000149857, upgrade Apache Tomcat to a version later than 11.0.0-M26 or 10.1.3.
F5-K000149857 affects Apache Tomcat versions from 11.0.0-M23 through 11.0.0-M26 and from 10.1.27 through 10.1.3.
F5-K000149857 is an incorrect object recycling and re-use vulnerability affecting HTTP/2 requests.
Organizations using affected versions of Apache Tomcat with F5 Traffix SDC 5.2.0 are at risk due to F5-K000149857.