CVE Vulnerabilities

CVE-2011-3190

Published: Aug 31, 2011 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 7.0.12 7.0.12
Tomcat Apache 7.0.20 7.0.20
Tomcat Apache 7.0.8 7.0.8
Tomcat Apache 7.0.1 7.0.1
Tomcat Apache 7.0.2 7.0.2
Tomcat Apache 7.0.5 7.0.5
Tomcat Apache 7.0.0 7.0.0
Tomcat Apache 7.0.6 7.0.6
Tomcat Apache 7.0.14 7.0.14
Tomcat Apache 7.0.11 7.0.11
Tomcat Apache 7.0.0 7.0.0
Tomcat Apache 7.0.7 7.0.7
Tomcat Apache 7.0.13 7.0.13
Tomcat Apache 7.0.19 7.0.19
Tomcat Apache 7.0.16 7.0.16
Tomcat Apache 7.0.10 7.0.10
Tomcat Apache 7.0.17 7.0.17
Tomcat Apache 7.0.9 7.0.9
Tomcat Apache 7.0.4 7.0.4
Tomcat Apache 7.0.3 7.0.3

References