CVE-2007-6286

Impact:
Important
Public Date:
2008-02-08
Bugzilla:
432332: CVE-2007-6286 Tomcat5 Data integrity

The MITRE CVE dictionary describes this issue as:

Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.

Find out more about CVE-2007-6286 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not Vulnerable. Red Hat does not ship a version of Apache Tomcat that enables the native APR connector.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.