AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-6286

MEDIUM · CVSS 4.3 EPSS 5.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-02-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-6286
Severity
MEDIUM
CVSS
4.3
EPSS
5.37%
Apache

Original NVD Description

Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.