CVE-2006-7197

EPSS 2.7%

Apache Tomcat Buffer Over-Read

Published: 5/1/2022Modified: 4/9/2025

Description

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the `ajp_process_callback` in mod_jk, which allows remote attackers to read portions of sensitive memory.

Affected packages (1)

References (20)