UNKNOWN Maven

Apache Tomcat Buffer Over-Read

GHSA-jpqr-vh55-xqxf · CVE-2006-7197

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes