Vulnerability Description
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | 6.0.0 |
Related Weaknesses (CWE)
References
- http://www.arubanetworks.com/assets/alert/HPESBHF03730.txt
- http://www.debian.org/security/2017/dsa-3842
- http://www.debian.org/security/2017/dsa-3843
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.securitytracker.com/id/1038218
- https://access.redhat.com/errata/RHSA-2017:1801
- https://access.redhat.com/errata/RHSA-2017:1802
- https://access.redhat.com/errata/RHSA-2017:2493
- https://access.redhat.com/errata/RHSA-2017:2494
- https://access.redhat.com/errata/RHSA-2017:3080
- https://access.redhat.com/errata/RHSA-2017:3081
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e8
- https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbea
- https://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c
FAQ
What is CVE-2017-5647?
CVE-2017-5647 is a vulnerability with a CVSS score of 7.5 (HIGH). A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in ...
How severe is CVE-2017-5647?
CVE-2017-5647 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-5647?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.