CVE-2007-6286
mediumCVSS v3 Base Score
4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Score
9.5%
Exploitation probability in 30 days
Top 7% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
P
Availability
None
Published: February 12, 2008 (6666 days ago)
Last Modified: April 23, 2026
Vendor: Apache
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
CWE
NVD-CWE-OtherAffected Products
apache tomcat