CVE-2008-5519 PUBLISHED CVSS 2.5999999046325684 LOW

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.

EPSS 4.56% · 89.1th percentile

Risk Scores

CVSS v2.0
2.5999999046325684
EPSS Score
4.56%
89.1th percentile

Affected Products

VendorProductVersions
apachetomcat5.5.27, 5.5.2, 5.5.3
apachemod_jk1.2, 1.2.1, 1.2.6
n/an/an/a

Timeline

References

…and 14 more

Open in Interactive Console →