CVE Vulnerabilities

CVE-2011-3190

Published: Aug 31, 2011 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 7.0.0 (including) 7.0.0 (including)
Tomcat Apache 7.0.0-beta (including) 7.0.0-beta (including)
Tomcat Apache 7.0.1 (including) 7.0.1 (including)
Tomcat Apache 7.0.2 (including) 7.0.2 (including)
Tomcat Apache 7.0.3 (including) 7.0.3 (including)
Tomcat Apache 7.0.4 (including) 7.0.4 (including)
Tomcat Apache 7.0.5 (including) 7.0.5 (including)
Tomcat Apache 7.0.6 (including) 7.0.6 (including)
Tomcat Apache 7.0.7 (including) 7.0.7 (including)
Tomcat Apache 7.0.8 (including) 7.0.8 (including)
Tomcat Apache 7.0.9 (including) 7.0.9 (including)
Tomcat Apache 7.0.10 (including) 7.0.10 (including)
Tomcat Apache 7.0.11 (including) 7.0.11 (including)
Tomcat Apache 7.0.12 (including) 7.0.12 (including)
Tomcat Apache 7.0.13 (including) 7.0.13 (including)
Tomcat Apache 7.0.14 (including) 7.0.14 (including)
Tomcat Apache 7.0.16 (including) 7.0.16 (including)
Tomcat Apache 7.0.17 (including) 7.0.17 (including)
Tomcat Apache 7.0.19 (including) 7.0.19 (including)
Tomcat Apache 7.0.20 (including) 7.0.20 (including)
Red Hat Enterprise Linux 6 RedHat tomcat6-0:6.0.24-35.el6_1 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat tomcat5-0:5.5.33-27_patch_07.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat tomcat6-0:6.0.32-24_patch_07.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat tomcat5-0:5.5.33-28_patch_07.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat tomcat6-0:6.0.32-24_patch_07.ep5.el6 *
Red Hat JBoss Web Server 1.0 RedHat *
Red Hat JBoss Web Server 1.0 RedHat *
Tomcat5.5 Ubuntu hardy *
Tomcat5.5 Ubuntu upstream *
Tomcat6 Ubuntu lucid *
Tomcat6 Ubuntu maverick *
Tomcat6 Ubuntu natty *
Tomcat6 Ubuntu upstream *
Tomcat7 Ubuntu devel *
Tomcat7 Ubuntu oneiric *
Tomcat7 Ubuntu upstream *

References