Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Tomcat SSL端口空请求 设计错误漏洞
Vulnerability Description
Apache Tomcat,当原本的 ARP 连接被使用时,不能恰当地处理 SSL 端口的空请求,导致允许远程攻击者触发一个最近请求的双份拷贝处理,使用 netcat 发送空请求证明了这一点。
CVSS Information
N/A
Vulnerability Type
N/A