Vulnerability Description
The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Cosminexus Application Server | 05_00_05_05_e |
| Apache | Tomcat | >= 4.0.1, <= 4.0.6 |
Related Weaknesses (CWE)
References
- http://jvn.jp/jp/JVN%2379314822/index.htmlVDB Entry
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlMailing ListThird Party Advisory
- http://secunia.com/advisories/17019Broken LinkVendor Advisory
- http://secunia.com/advisories/30802Broken LinkVendor Advisory
- http://secunia.com/advisories/30899Broken LinkVendor Advisory
- http://secunia.com/advisories/30908Broken LinkVendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-239312-1Broken Link
- http://support.apple.com/kb/HT2163Third Party Advisory
- http://tomcat.apache.org/security-4.htmlVendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS05-019_e/01-e.htmlThird Party Advisory
- http://www.securityfocus.com/bid/15003Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2008/1979/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/1981/referencesVendor Advisory
- https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bd
- https://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c
FAQ
What is CVE-2005-3164?
CVE-2005-3164 is a vulnerability with a CVSS score of 2.6 (LOW). The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken b...
How severe is CVE-2005-3164?
CVE-2005-3164 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3164?
Check the references section above for vendor advisories and patch information. Affected products include: Hitachi Cosminexus Application Server, Apache Tomcat.