Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2401-1 | tomcat6 security update |
EUVD |
EUVD-2022-5209 | Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data. |
Github GHSA |
GHSA-rp8h-vr48-4j8p | Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests |
Ubuntu USN |
USN-1359-1 | Tomcat vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T23:29:56.702Z
Reserved: 2011-08-30T00:00:00
Link: CVE-2011-3375
No data.
Status : Deferred
Published: 2012-01-19T04:01:16.927
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-3375
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA
Ubuntu USN