Apache Tomcat's doRead error handling flaw, tracked as CVE-2008-4308, can cause POST content from one HTTP request to be sent with a different request. The information-disclosure issue affects Tomcat versions 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20; it results from doRead failing to return -1 under a particular error condition.
Apache's Tomcat 4.x vulnerability documentation continues to list this and other historical flaws affecting the obsolete 4.0.x and 4.1.x branches, including disclosure, denial-of-service, traversal, XSS, session-hijacking, and security-manager-bypass issues. Those branches are unsupported and will not receive further security fixes; organizations running affected releases should upgrade to a supported Tomcat version, at minimum Tomcat 7.x or later as advised in the documentation.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
CVE-2008-4308 was published for an Apache Tomcat doRead error-handling flaw that could send POST content from one HTTP request with another request. The issue affected Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcelists.apache.org
Open sourcelists.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.