When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
                                
                                
  | 
                        
Information
                Published : 2021-03-01 04:15
Updated : 2022-10-25 11:07
NVD link : CVE-2021-25122
Mitre link : CVE-2021-25122
JSON object : View
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
                oracle
- siebel_ui_framework
 - database
 - mysql_enterprise_monitor
 - communications_cloud_native_core_security_edge_protection_proxy
 - instantis_enterprisetrack
 - communications_instant_messaging_server
 - graph_server_and_client
 - agile_plm
 - communications_cloud_native_core_policy
 - managed_file_transfer
 
apache
- tomcat
 
debian
- debian_linux
 


