CVE-2011-3190
Last modified
CVE-2011-3190 is a vulnerability of currently unknown severity. Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.. EPSS estimates a 15.23% chance of exploitation in the next 30 days.
Description
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | 7.0.0 |
| Apache | Tomcat | 7.0.1 |
| Apache | Tomcat | 7.0.2 |
| Apache | Tomcat | 7.0.3 |
| Apache | Tomcat | 7.0.4 |
| Apache | Tomcat | 7.0.5 |
| Apache | Tomcat | 7.0.6 |
| Apache | Tomcat | 7.0.7 |
| Apache | Tomcat | 7.0.8 |
| Apache | Tomcat | 7.0.9 |
| Apache | Tomcat | 7.0.10 |
| Apache | Tomcat | 7.0.11 |
| Apache | Tomcat | 7.0.12 |
| Apache | Tomcat | 7.0.13 |
| Apache | Tomcat | 7.0.14 |
| Apache | Tomcat | 7.0.16 |
| Apache | Tomcat | 7.0.17 |
| Apache | Tomcat | 7.0.19 |
| Apache | Tomcat | 7.0.20 |
| Apache | Tomcat | 6.0 |
| Apache | Tomcat | 6.0.0 |
| Apache | Tomcat | 6.0.1 |
| Apache | Tomcat | 6.0.2 |
| Apache | Tomcat | 6.0.3 |
| Apache | Tomcat | 6.0.4 |
| Apache | Tomcat | 6.0.5 |
| Apache | Tomcat | 6.0.6 |
| Apache | Tomcat | 6.0.7 |
| Apache | Tomcat | 6.0.8 |
| Apache | Tomcat | 6.0.9 |
| Apache | Tomcat | 6.0.10 |
| Apache | Tomcat | 6.0.11 |
| Apache | Tomcat | 6.0.12 |
| Apache | Tomcat | 6.0.13 |
| Apache | Tomcat | 6.0.14 |
| Apache | Tomcat | 6.0.15 |
| Apache | Tomcat | 6.0.16 |
| Apache | Tomcat | 6.0.17 |
| Apache | Tomcat | 6.0.18 |
| Apache | Tomcat | 6.0.19 |
| Apache | Tomcat | 6.0.20 |
| Apache | Tomcat | 6.0.24 |
| Apache | Tomcat | 6.0.26 |
| Apache | Tomcat | 6.0.27 |
| Apache | Tomcat | 6.0.28 |
| Apache | Tomcat | 6.0.29 |
| Apache | Tomcat | 6.0.30 |
| Apache | Tomcat | 6.0.31 |
| Apache | Tomcat | 6.0.32 |
| Apache | Tomcat | 6.0.33 |
Showing 50 of 84 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/45748Vendor Advisory
- http://secunia.com/advisories/45748Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-3190?
How severe is CVE-2011-3190?
How do I fix CVE-2011-3190?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-3184The msn_httpconn_parse_data function in httpconn.c in the MS…
- CVE-2011-3185gtkutils.c in Pidgin before 2.10.0 on Windows allows user-as…
- CVE-2011-3186CRLF injection vulnerability in actionpack/lib/action_contro…
- CVE-2011-3187The to_s method in actionpack/lib/action_dispatch/middleware…
- CVE-2011-3188The (1) IPv4 and (2) IPv6 implementations in the Linux kerne…9.1
- CVE-2011-3189The crypt function in PHP 5.3.7, when the MD5 hash type is u…
- CVE-2011-3191Integer signedness error in the CIFSFindNext function in fs/…8.8
- CVE-2011-3192The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x …
- CVE-2011-3193Heap-based buffer overflow in the Lookup_MarkMarkPos functio…
- CVE-2011-3194Buffer overflow in the TIFF reader in gui/image/qtiffhandler…
- CVE-2011-3195shared/inc/sql/lists.php in Domain Technologie Control (DTC)…
- CVE-2011-3196The setup script in Domain Technologie Control (DTC) before …
Are you affected by CVE-2011-3190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
