CVE Vulnerabilities

CVE-2011-3190

Published: Aug 31, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache7.0.0 (including)7.0.0 (including)
TomcatApache7.0.0-beta (including)7.0.0-beta (including)
TomcatApache7.0.1 (including)7.0.1 (including)
TomcatApache7.0.2 (including)7.0.2 (including)
TomcatApache7.0.3 (including)7.0.3 (including)
TomcatApache7.0.4 (including)7.0.4 (including)
TomcatApache7.0.5 (including)7.0.5 (including)
TomcatApache7.0.6 (including)7.0.6 (including)
TomcatApache7.0.7 (including)7.0.7 (including)
TomcatApache7.0.8 (including)7.0.8 (including)
TomcatApache7.0.9 (including)7.0.9 (including)
TomcatApache7.0.10 (including)7.0.10 (including)
TomcatApache7.0.11 (including)7.0.11 (including)
TomcatApache7.0.12 (including)7.0.12 (including)
TomcatApache7.0.13 (including)7.0.13 (including)
TomcatApache7.0.14 (including)7.0.14 (including)
TomcatApache7.0.16 (including)7.0.16 (including)
TomcatApache7.0.17 (including)7.0.17 (including)
TomcatApache7.0.19 (including)7.0.19 (including)
TomcatApache7.0.20 (including)7.0.20 (including)
Red Hat Enterprise Linux 6RedHattomcat6-0:6.0.24-35.el6_1*
Red Hat JBoss Enterprise Web Server 1 for RHEL 5RedHattomcat5-0:5.5.33-27_patch_07.ep5.el5*
Red Hat JBoss Enterprise Web Server 1 for RHEL 5RedHattomcat6-0:6.0.32-24_patch_07.ep5.el5*
Red Hat JBoss Enterprise Web Server 1 for RHEL 6RedHattomcat5-0:5.5.33-28_patch_07.ep5.el6*
Red Hat JBoss Enterprise Web Server 1 for RHEL 6RedHattomcat6-0:6.0.32-24_patch_07.ep5.el6*
Red Hat JBoss Web Server 1.0RedHat*
Red Hat JBoss Web Server 1.0RedHat*
Tomcat5.5Ubuntuhardy*
Tomcat5.5Ubuntuupstream*
Tomcat6Ubuntulucid*
Tomcat6Ubuntumaverick*
Tomcat6Ubuntunatty*
Tomcat6Ubuntuupstream*
Tomcat7Ubuntudevel*
Tomcat7Ubuntuoneiric*
Tomcat7Ubuntuupstream*

References