CVE-2008-5519

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
09/04/2009
Last modified:
09/04/2025

Description

The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:mod_jk:1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.9:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.11:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.12:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.13:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.14:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.14.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.15:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.16:*:*:*:*:*:*:*
cpe:2.3:a:apache:mod_jk:1.2.17:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools