SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-3164

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request,…

LOW 2.6EPSS 6.52%

Does this matter?

Lower severity and a low EPSS score (6.52%). Track it; it rarely justifies an emergency change on its own.

Description

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS
6.52% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
hitachi/cosminexus application server · apache/tomcat
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.