Posted by Mark Thomas on Apr 06
CVE-2011-1475 Apache Tomcat information disclosure
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected:
– Tomcat 7.0.0 to 7.0.11
– Earlier versions are not affected
Description:
Changes introduced to the HTTP BIO connector to support Servlet 3.0
asynchronous requests did not fully account for HTTP pipelining. As a
result, when using HTTP pipelining a range of unexpected behaviours
occurred including the mixing up of…
Source: [SECURITY] CVE-2011-1475 Apache Tomcat information disclosure




