VDB
CVE-2011-1475
CVE-2011-1475
PUBLISHED
CVSS 5 MEDIUM
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
EPSS 11.70% · 93.8th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
11.70%
93.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apache | tomcat | 7.0.4, 7.0.0, 7.0.0 |
| Maven | org.apache.tomcat:tomcat | 7.0.0 |
| n/a | n/a | * |
Timeline
- Apr 8, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- ADV-2011-0894 vdb
- 47199 vdb
- oval:org.mitre.oval:def:12374 vdb
- 8188 third-party-advisory
- http://tomcat.apache.org/security-7.html url
- 1025303 vdb
- https://issues.apache.org/bugzilla/show_bug.cgi?id=50957 url
- 20110406 [SECURITY] CVE-2011-1475 Apache Tomcat information disclosure mailing-list
- http://svn.apache.org/viewvc?view=revision&revision=1086349 url
- http://svn.apache.org/viewvc?view=revision&revision=1086352 url
- 20110406 [SECURITY] CVE-2011-1475 Apache Tomcat information disclosure mailing-list
- tomcat-httpbio-info-disclosure(66676) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2011-1475 advisory
- https://github.com/apache/tomcat/commit/d2e8f2ede7dea39f75f68384f331f38f094e4ed3 url
- https://github.com/apache/tomcat/commit/fd8a579e0e2379a84826b11700adf396e4ed2041 url
- https://github.com/apache/tomcat url
- https://web.archive.org/web/20120605200856/http://www.securityfocus.com/bid/47199 url
- https://web.archive.org/web/20170202012852/http://www.securityfocus.com/archive/1/517363 url
- https://web.archive.org/web/20170317142459/http://www.securitytracker.com/id?1025303 url