Information disclosure in Apache Tomcat JK ISAPI Connector - CVE-2008-5519
Published: October 7, 2016
Vulnerability identifier: #VU796
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2008-5519
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Apache Foundation
Affected software:
Apache Tomcat JK ISAPI Connector
Apache Tomcat JK ISAPI Connector
Detailed vulnerability description
The vulnerability allows a remote uauthenticated user to read potentially sensitive information on the target system.
The weakness exists due to insufficient access control. If the valid user sets Content-Length without providing data or sends requests too promptly, attackers can view the responses to that requests.
Successful exploitation of the vulnerability results in information disclosure.
The weakness exists due to insufficient access control. If the valid user sets Content-Length without providing data or sends requests too promptly, attackers can view the responses to that requests.
Successful exploitation of the vulnerability results in information disclosure.
How to mitigate CVE-2008-5519
Update to version 1.2.27.