CVE-2016-8747

An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:8.5.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:8.5.8:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:8.5.9:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*

History

No history.

Information

Published : 2017-03-14 09:59

Updated : 2023-12-08 16:41


NVD link : CVE-2016-8747

Mitre link : CVE-2016-8747

CVE.ORG link : CVE-2016-8747


JSON object : View

Products Affected

apache

  • tomcat
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor