Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a synchronization problem and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tomcat | Apache | 4.1.0 (including) | 4.1.0 (including) |
Tomcat | Apache | 4.1.1 (including) | 4.1.1 (including) |
Tomcat | Apache | 4.1.2 (including) | 4.1.2 (including) |
Tomcat | Apache | 4.1.3 (including) | 4.1.3 (including) |
Tomcat | Apache | 4.1.3-beta (including) | 4.1.3-beta (including) |
Tomcat | Apache | 4.1.4 (including) | 4.1.4 (including) |
Tomcat | Apache | 4.1.5 (including) | 4.1.5 (including) |
Tomcat | Apache | 4.1.6 (including) | 4.1.6 (including) |
Tomcat | Apache | 4.1.7 (including) | 4.1.7 (including) |
Tomcat | Apache | 4.1.8 (including) | 4.1.8 (including) |
Tomcat | Apache | 4.1.9 (including) | 4.1.9 (including) |
Tomcat | Apache | 4.1.10 (including) | 4.1.10 (including) |
Tomcat | Apache | 4.1.11 (including) | 4.1.11 (including) |
Tomcat | Apache | 4.1.12 (including) | 4.1.12 (including) |
Tomcat | Apache | 4.1.13 (including) | 4.1.13 (including) |
Tomcat | Apache | 4.1.14 (including) | 4.1.14 (including) |
Tomcat | Apache | 4.1.15 (including) | 4.1.15 (including) |
Tomcat | Apache | 4.1.16 (including) | 4.1.16 (including) |
Tomcat | Apache | 4.1.17 (including) | 4.1.17 (including) |
Tomcat | Apache | 4.1.18 (including) | 4.1.18 (including) |
Tomcat | Apache | 4.1.19 (including) | 4.1.19 (including) |
Tomcat | Apache | 4.1.20 (including) | 4.1.20 (including) |
Tomcat | Apache | 4.1.21 (including) | 4.1.21 (including) |
Tomcat | Apache | 4.1.22 (including) | 4.1.22 (including) |
Tomcat | Apache | 4.1.23 (including) | 4.1.23 (including) |
Tomcat | Apache | 4.1.24 (including) | 4.1.24 (including) |
Tomcat | Apache | 4.1.25 (including) | 4.1.25 (including) |
Tomcat | Apache | 4.1.26 (including) | 4.1.26 (including) |
Tomcat | Apache | 4.1.27 (including) | 4.1.27 (including) |
Tomcat | Apache | 4.1.28 (including) | 4.1.28 (including) |
Tomcat | Apache | 4.1.29 (including) | 4.1.29 (including) |
Tomcat | Apache | 4.1.30 (including) | 4.1.30 (including) |
Tomcat | Apache | 4.1.31 (including) | 4.1.31 (including) |
Tomcat | Apache | 5.5.0 (including) | 5.5.0 (including) |
Tomcat4 | Ubuntu | dapper | * |
Tomcat5 | Ubuntu | dapper | * |
Tomcat5 | Ubuntu | feisty | * |
Tomcat5.5 | Ubuntu | feisty | * |
Tomcat5.5 | Ubuntu | gutsy | * |
Tomcat5.5 | Ubuntu | upstream | * |
Red Hat Network Satellite Server v 5.0 | RedHat | tomcat5-0:5.0.30-0jpp_12rh | * |
Red Hat Network Satellite Server v 5.1 | RedHat | tomcat5-0:5.0.30-0jpp_12rh | * |