CVE-2017-5647 Details
Description
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.0.6 6.0.7 6.0.8 6.0.9 6.0.10 6.0.11 6.0.12 6.0.13 6.0.14 6.0.15 6.0.16 6.0.17 6.0.18 6.0.19 6.0.20 6.0.21 6.0.22 6.0.23 6.0.24 6.0.25 6.0.26 6.0.27 6.0.28 6.0.29 6.0.30 6.0.31 6.0.32 6.0.33 6.0.34 6.0.35 6.0.36 6.0.37 6.0.38 6.0.39 6.0.40 6.0.41 6.0.42 6.0.43 6.0.44 6.0.45 6.0.46 6.0.47 6.0.48 6.0.49 6.0.50 6.0.51 6.0.52 7.0.0 7.0.1 7.0.2 7.0.3 7.0.4 7.0.5 7.0.6 7.0.7 7.0.8 7.0.9 7.0.10 7.0.11 7.0.12 7.0.13 7.0.14 7.0.15 7.0.16 7.0.17 7.0.18 7.0.19 7.0.20 7.0.21 7.0.22 7.0.23 7.0.24 7.0.25 7.0.26 7.0.27 7.0.28 7.0.29 7.0.30 7.0.31 7.0.32 7.0.33 7.0.34 7.0.35 7.0.36 7.0.37 7.0.38 7.0.39 7.0.40 7.0.41 7.0.42 7.0.43 7.0.44 7.0.45 7.0.46 7.0.47 7.0.48 7.0.49 7.0.50 7.0.51 7.0.52 7.0.53 7.0.54 7.0.55 7.0.56 7.0.57 7.0.58 7.0.59 7.0.60 7.0.61 7.0.62 7.0.63 7.0.64 7.0.65 7.0.66 7.0.67 7.0.68 7.0.69 7.0.70 7.0.71 7.0.72 7.0.73 7.0.74 7.0.75 7.0.76 8.0.0 8.0.0 rc1 8.0.1 8.0.2 8.0.3 8.0.4 8.0.5 8.0.6 8.0.7 8.0.8 8.0.9 8.0.10 8.0.11 8.0.12 8.0.13 8.0.14 8.0.15 8.0.16 8.0.17 8.0.18 8.0.19 8.0.20 8.0.21 8.0.22 8.0.23 8.0.24 8.0.25 8.0.26 8.0.27 8.0.28 8.0.29 8.0.30 8.0.31 8.0.32 8.0.33 8.0.34 8.0.35 8.0.36 8.0.37 8.0.38 8.0.39 8.0.40 8.0.41 8.0.42 8.5.0 8.5.1 8.5.2 8.5.3 8.5.4 8.5.5 8.5.6 8.5.7 8.5.8 8.5.9 8.5.10 8.5.11 8.5.12 9.0.0 milestone1 9.0.0 milestone10 9.0.0 milestone11 9.0.0 milestone12 9.0.0 milestone13 9.0.0 milestone14 9.0.0 milestone15 9.0.0 milestone16 9.0.0 milestone17 9.0.0 milestone18 9.0.0 milestone2 9.0.0 milestone3 9.0.0 milestone4 9.0.0 milestone5 9.0.0 milestone6 9.0.0 milestone7 9.0.0 milestone8 9.0.0 milestone9 |
CPE
Remediation
| |
Change History
40 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Feb 13, 2020 | CVE Modified | [email protected] |
| Feb 3, 2020 | CVE Modified | [email protected] |
| Jul 23, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Mar 25, 2019 | CVE Modified | [email protected] |
| Mar 21, 2019 | CVE Modified | [email protected] |
| Jun 16, 2018 | CVE Modified | [email protected] |
| Mar 8, 2018 | CVE Modified | [email protected] |
| Jan 5, 2018 | CVE Modified | [email protected] |
| Dec 2, 2017 | CVE Modified | [email protected] |
| Nov 4, 2017 | CVE Modified | [email protected] |
| Aug 9, 2017 | CVE Modified | [email protected] |
| Jul 11, 2017 | CVE Modified | [email protected] |
| Jul 1, 2017 | CVE Modified | [email protected] |
| May 30, 2017 | CVE Modified | [email protected] |
| Apr 21, 2017 | Initial Analysis | [email protected] |