Bugzilla – Bug 1029460
VUL-0: CVE-2016-8747: tomcat: Information leak between requests on the same connection
Last modified: 2017-03-21 14:15:37 UTC
rh#1432006 An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request. References: https://bugzilla.redhat.com/show_bug.cgi?id=1432006 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-8747 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-8747.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8747 http://svn.apache.org/viewvc?view=revision&revision=1774166 http://svn.apache.org/viewvc?view=revision&revision=1774161
we are not affected