LOW · 2.6

CVE-2005-3164

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken b...

Vulnerability Description

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

CVSS Score

2.6

LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HitachiCosminexus Application Server05_00_05_05_e
ApacheTomcat>= 4.0.1, <= 4.0.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2005-3164?

CVE-2005-3164 is a vulnerability with a CVSS score of 2.6 (LOW). The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken b...

How severe is CVE-2005-3164?

CVE-2005-3164 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-3164?

Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Cosminexus Application Server, Apache Tomcat.