CVE-2011-3190
Apache Tomcat Allows Remote Attackers to Spoof AJP Requests
EPSS 15.2%
描述
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
如何修補 CVE-2011-3190
要修補 CVE-2011-3190,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 7.0.21 或更新版本
CVE-2011-3190 正在被利用嗎?
中等 — EPSS 為 15.2%,可持續追蹤但非最高優先。
受影響套件(1)
- >= 7.0.0, < 7.0.21