CVE-2008-4308
lowCVSS v3 Base Score
2.6
AV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS Score
7.6%
Exploitation probability in 30 days
Top 8% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Confidentiality
P
Integrity
None
Availability
None
Published: February 26, 2009 (6285 days ago)
Last Modified: April 23, 2026
Vendor: Apache
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.
CWE
CWE-200Affected Products
apache tomcat