CVE-2005-3164

low Apache
CVSS v3 Base Score
2.6
AV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS Score
3.4%
Exploitation probability in 30 days
Top 13% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Confidentiality
P
Integrity
None
Availability
None
Published: October 6, 2005 (7525 days ago)
Last Modified: April 16, 2026
Vendor: Apache
Source: NVD

Description

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

CWE

CWE-200

Affected Products

hitachi cosminexus application serverapache tomcat

References