AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-5647

HIGH · CVSS 7.5 EPSS 16.84%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-04-17 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Apache. Its EPSS score suggests a 16.8% probability of exploitation in the next 30 days.

CVE
CVE-2017-5647
Severity
HIGH
CVSS
7.5
EPSS
16.84%
Apache

Original NVD Description

A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.

Related CVEs

Other vulnerabilities affecting the same vendor(s)