AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-3164

LOW · CVSS 2.6 EPSS 6.52%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-10-06 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 2.6. It affects Apache, Java.

CVE
CVE-2005-3164
Severity
LOW
CVSS
2.6
EPSS
6.52%
Apache Java

Original NVD Description

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.