CVE-2007-6286
Apache Tomcat Does Not Properly Handle Empty Requests
EPSS 10.0%
Description
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
How to fix CVE-2007-6286
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Maven/org.apache.tomcat:tomcat—no fix listed
Is CVE-2007-6286 being exploited?
Moderate — EPSS is 10.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 5.5.11, <= 5.5.25