[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2017-796 ---- tomcat7 tomcat8

ID: oval:org.secpod.oval:def:1600504Date: (C)2017-03-21   (M)2023-12-20
Class: PATCHFamily: unix




A bug in the error handling of the send file code for the NIO HTTP connector resulted in the current Processor object being added to the Processor cache multiple times. This in turn meant that the same Processor could be used for concurrent requests. Sharing a Processor can result in information leakage between requests including, not not limited to, session ID and the response body.

Platform:
Amazon Linux AMI
Product:
tomcat7
tomcat8
Reference:
ALAS-2017-796
CVE-2016-8745
CVE    1
CVE-2016-8745
CPE    3
cpe:/o:amazon:linux
cpe:/a:apache:tomcat8
cpe:/a:apache:tomcat7

© SecPod Technologies