CVE-2007-6286
Last modified
CVE-2007-6286 is a vulnerability of currently unknown severity. Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.. EPSS estimates a 5.37% chance of exploitation in the next 30 days.
Description
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | 5.5.11 |
| Apache | Tomcat | 5.5.12 |
| Apache | Tomcat | 5.5.13 |
| Apache | Tomcat | 5.5.14 |
| Apache | Tomcat | 5.5.15 |
| Apache | Tomcat | 5.5.16 |
| Apache | Tomcat | 5.5.17 |
| Apache | Tomcat | 5.5.18 |
| Apache | Tomcat | 5.5.19 |
| Apache | Tomcat | 5.5.20 |
| Apache | Tomcat | 5.5.21 |
| Apache | Tomcat | 5.5.22 |
| Apache | Tomcat | 5.5.23 |
| Apache | Tomcat | 5.5.24 |
| Apache | Tomcat | 5.5.25 |
| Apache | Tomcat | 6.0.0 |
| Apache | Tomcat | 6.0.1 |
| Apache | Tomcat | 6.0.2 |
| Apache | Tomcat | 6.0.3 |
| Apache | Tomcat | 6.0.4 |
| Apache | Tomcat | 6.0.5 |
| Apache | Tomcat | 6.0.6 |
| Apache | Tomcat | 6.0.7 |
| Apache | Tomcat | 6.0.8 |
| Apache | Tomcat | 6.0.9 |
| Apache | Tomcat | 6.0.10 |
| Apache | Tomcat | 6.0.11 |
| Apache | Tomcat | 6.0.12 |
| Apache | Tomcat | 6.0.13 |
| Apache | Tomcat | 6.0.14 |
| Apache | Tomcat | 6.0.15 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6286?
How severe is CVE-2007-6286?
How do I fix CVE-2007-6286?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6279Multiple double free vulnerabilities in Free Lossless Audio …
- CVE-2007-6281Heap-based buffer overflow in Open File Manager service (ofm…
- CVE-2007-6282The IPsec implementation in Linux kernel before 2.6.25 allow…
- CVE-2007-6283Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/…
- CVE-2007-6284The xmlCurrentChar function in libxml2 before 2.6.31 allows …
- CVE-2007-6285The default configuration for autofs 5 (autofs5) in some Lin…
- CVE-2007-6287Cross-site scripting (XSS) vulnerability in the login page i…
- CVE-2007-6288Multiple SQL injection vulnerabilities in TCExam before 5.1.…
- CVE-2007-6289Multiple PHP remote file inclusion vulnerabilities in SerWeb…
- CVE-2007-6290Multiple directory traversal vulnerabilities in js/get_js.ph…
- CVE-2007-6291SQL injection vulnerability in abm.aspx in Xigla Absolute Ba…
- CVE-2007-6292SQL injection vulnerability in leggi_commenti.asp in MWOpen …
Are you affected by CVE-2007-6286?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
