CVE-2008-4308
26.02.2009, 23:30
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.Enginsight
Vendor | Product | Version |
---|---|---|
apache | tomcat | 4.1.32 |
apache | tomcat | 4.1.33 |
apache | tomcat | 4.1.34 |
apache | tomcat | 5.5.10 |
apache | tomcat | 5.5.11 |
apache | tomcat | 5.5.12 |
apache | tomcat | 5.5.13 |
apache | tomcat | 5.5.14 |
apache | tomcat | 5.5.15 |
apache | tomcat | 5.5.16 |
apache | tomcat | 5.5.17 |
apache | tomcat | 5.5.18 |
apache | tomcat | 5.5.19 |
apache | tomcat | 5.5.20 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References