CVE-2011-3375

EUVD-2022-5209
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
apachetomcat
6.0.30
apachetomcat
6.0.31
apachetomcat
6.0.32
apachetomcat
6.0.33
apachetomcat
7.0.0
apachetomcat
7.0.1
apachetomcat
7.0.2
apachetomcat
7.0.3
apachetomcat
7.0.4
apachetomcat
7.0.5
apachetomcat
7.0.6
apachetomcat
7.0.7
apachetomcat
7.0.8
apachetomcat
7.0.9
apachetomcat
7.0.10
apachetomcat
7.0.11
apachetomcat
7.0.12
apachetomcat
7.0.13
apachetomcat
7.0.14
apachetomcat
7.0.15
apachetomcat
7.0.16
apachetomcat
7.0.17
apachetomcat
7.0.18
apachetomcat
7.0.19
apachetomcat
7.0.20
apachetomcat
7.0.21
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat5.5
hardy
ignored
lucid
dne
maverick
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
tomcat6
hardy
dne
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
Fixed 6.0.32-5ubuntu1.2
released
precise
not-affected
quantal
not-affected
tomcat7
hardy
dne
lucid
dne
maverick
dne
natty
dne
oneiric
Fixed 7.0.21-1ubuntu0.1
released
precise
not-affected
quantal
not-affected