Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
References
Link Providers
http://marc.info/?l=bugtraq&m=132215163318824&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=133469267822771&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136485229118404&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=139344343412337&w=2 cve-icon cve-icon
http://secunia.com/advisories/45748 cve-icon cve-icon
http://secunia.com/advisories/48308 cve-icon cve-icon
http://secunia.com/advisories/49094 cve-icon cve-icon
http://secunia.com/advisories/57126 cve-icon cve-icon
http://securityreason.com/securityalert/8362 cve-icon cve-icon
http://www.debian.org/security/2012/dsa-2401 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2011:156 cve-icon cve-icon
http://www.securityfocus.com/archive/1/519466/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/49353 cve-icon cve-icon
http://www.securitytracker.com/id?1025993 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/69472 cve-icon cve-icon
https://issues.apache.org/bugzilla/show_bug.cgi?id=51698 cve-icon cve-icon
https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2011-3190 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14933 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19465 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2011-3190 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2011-08-31T23:00:00

Updated: 2024-08-06T23:29:55.291Z

Reserved: 2011-08-19T00:00:00

Link: CVE-2011-3190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-08-31T23:55:03.550

Modified: 2024-11-21T01:29:56.457

Link: CVE-2011-3190

cve-icon Redhat

Severity : Moderate

Publid Date: 2011-08-20T00:00:00Z

Links: CVE-2011-3190 - Bugzilla