Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-1475

23
FAUCET Score

CVE-2011-1475 describes a vulnerability in Apache Tomcat 7.0.x before 7.0.12, specifically affecting the HTTP BIO connector's handling of HTTP pipelining. This flaw allows remote attackers to potentially read responses intended for other clients, leading to information disclosure. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it is a medium-severity vulnerability, indicating low attack complexity and requiring no authentication, but only impacting confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
7.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:7.0.0:*:*:*:*:*:*:*
7.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
7.0.1CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:7.0.1:*:*:*:*:*:*:*
7.0.2CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:7.0.2:*:*:*:*:*:*:*
7.0.3CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:7.0.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
8.69%
Probability of exploitation in next 30 days
EPSS Percentile
94.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0869 is in the 93rd percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcatFixed in: 7.0.12

Vendor Advisories (2)

mavenGHSA-h6c8-rg87-f3pcmedium

Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users

May 17, 2022
redhatCVE-2011-1475Low

tomcat: Information disclosure due improper handling of HTTP pipelining

Apr 6, 2011

References

seclists.org / fulldisclosure/2011/Apr/97
securityreason.com / securityalert/8188
exchange.xforce.ibmcloud.com / vulnerabilities/66676
issues.apache.org / bugzilla/show_bug.cgi
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12374
svn.apache.org / viewvc
Patch
svn.apache.org / viewvc
Patch
tomcat.apache.org / security-7.html
Vendor Advisory
securityfocus.com / archive/1/517363
securityfocus.com / bid/47199
securitytracker.com / id
vupen.com / english/advisories/2011/0894