oval:org.mitre.oval:def:26527
Definition Id: oval:org.mitre.oval:def:26527 | |||
Oval ID: | oval:org.mitre.oval:def:26527 | ||
Title: | Allows context-dependent attackers to obtain sensitive request information | ||
Description: | java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2013-2071 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Apache Tomcat |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:12401 | |||
Oval ID: | oval:org.mitre.oval:def:12401 | ||
Title: | Apache Tomcat is installed | ||
Description: | Apache Tomcat is installed | ||
Family: | windows | Class: | inventory |
Reference(s): | cpe:/a:apache:tomcat | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Apache Tomcat |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:26527 |