4.3

CVE-2008-3271

Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version4.1.0
ApacheTomcat Version4.1.1
ApacheTomcat Version4.1.2
ApacheTomcat Version4.1.3
ApacheTomcat Version4.1.3 Updatebeta
ApacheTomcat Version4.1.4
ApacheTomcat Version4.1.5
ApacheTomcat Version4.1.6
ApacheTomcat Version4.1.7
ApacheTomcat Version4.1.8
ApacheTomcat Version4.1.9
ApacheTomcat Version4.1.10
ApacheTomcat Version4.1.11
ApacheTomcat Version4.1.12
ApacheTomcat Version4.1.13
ApacheTomcat Version4.1.14
ApacheTomcat Version4.1.15
ApacheTomcat Version4.1.16
ApacheTomcat Version4.1.17
ApacheTomcat Version4.1.18
ApacheTomcat Version4.1.19
ApacheTomcat Version4.1.20
ApacheTomcat Version4.1.21
ApacheTomcat Version4.1.22
ApacheTomcat Version4.1.23
ApacheTomcat Version4.1.24
ApacheTomcat Version4.1.25
ApacheTomcat Version4.1.26
ApacheTomcat Version4.1.27
ApacheTomcat Version4.1.28
ApacheTomcat Version4.1.29
ApacheTomcat Version4.1.30
ApacheTomcat Version4.1.31
ApacheTomcat Version5.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.3% 0.883
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N