CVE-2017-5647
tomcat8 - security update
7.5
HIGH
CVSS 3.1
EPSS 2.3%
Description
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.
How to fix CVE-2017-5647
To remediate CVE-2017-5647, upgrade the affected package to a fixed version below.
- —upgrade to 7.0.28-4+deb7u12 or later
- —upgrade to 7.0.56-3+deb8u10 or later
- —upgrade to 8.0.14-1+deb8u9 or later
- —upgrade to 9.0.0.M19 or later
Is CVE-2017-5647 being exploited?
Low — EPSS is 2.3%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 7.0.28-4+deb7u12
- from 0, < 7.0.56-3+deb8u10
- from 0, < 8.0.14-1+deb8u9
- >= 9.0.0.M1, < 9.0.0.M19
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |