Information disclosure in Apache Tomcat - CVE-2018-8037
Published: July 24, 2018 / Updated: July 25, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists due to improper handling of connection closures by the non-blocking I/O (NIO) and NIO2 connectors. A remote unauthenticated attacker can send a specially crafted request that submits malicious input, trigger bug in the tracking of connection closures, reuse user sessions in a new connection and access arbitrary data.
Affected software
JBoss Web Server
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for x86_64
Fedora
Opensuse
Dell Support Assist Enterprise
tomcat
How to mitigate CVE-2018-8037
Dell Support Assist Enterprise - update to 4.00.06.00
tomcat - addressed in versions 7.0.90-1.el6, 8.5.32-1.fc28
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- Amazon Linux AMI update for tomcat8
- Debian update for tomcat8
- OpenSUSE Linux update for tomcat
- Red Hat update for tomcat
- Red Hat update for tomcat
- OpenSUSE Linux update for tomcat
- Red Hat update for pki-deps:10.6
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Fedora EPEL 6 update for tomcat
- Fedora 28 update for tomcat