<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2017-5651</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2017-5651</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>11</Number>
        <Date>2025-11-05T04:06:19Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T13:52:56Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-11-05T04:06:19Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2017-5651</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could result in the same Processor being used for multiple requests which in turn could lead to unexpected errors and/or response mix-up.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1" CPE="cpe:/o:suse:sles:12:sp1">SUSE Linux Enterprise Server 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2" CPE="cpe:/o:suse:sles:12:sp2">SUSE Linux Enterprise Server 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS" CPE="cpe:/o:suse:sles-ltss:12">SUSE Linux Enterprise Server 12-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="tomcat">
      <FullProductName ProductID="tomcat" CPE="cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*">tomcat</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-admin-webapps">
      <FullProductName ProductID="tomcat-admin-webapps">tomcat-admin-webapps</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-docs-webapp">
      <FullProductName ProductID="tomcat-docs-webapp">tomcat-docs-webapp</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-el-2_2-api">
      <FullProductName ProductID="tomcat-el-2_2-api">tomcat-el-2_2-api</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-el-3_0-api">
      <FullProductName ProductID="tomcat-el-3_0-api">tomcat-el-3_0-api</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-javadoc">
      <FullProductName ProductID="tomcat-javadoc">tomcat-javadoc</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-jsp-2_2-api">
      <FullProductName ProductID="tomcat-jsp-2_2-api">tomcat-jsp-2_2-api</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-jsp-2_3-api">
      <FullProductName ProductID="tomcat-jsp-2_3-api">tomcat-jsp-2_3-api</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-lib">
      <FullProductName ProductID="tomcat-lib">tomcat-lib</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-servlet-3_0-api">
      <FullProductName ProductID="tomcat-servlet-3_0-api">tomcat-servlet-3_0-api</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-servlet-3_1-api">
      <FullProductName ProductID="tomcat-servlet-3_1-api">tomcat-servlet-3_1-api</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tomcat-webapps">
      <FullProductName ProductID="tomcat-webapps">tomcat-webapps</FullProductName>
    </Branch>
    <Relationship ProductReference="tomcat" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat">tomcat as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-admin-webapps" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-admin-webapps">tomcat-admin-webapps as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-docs-webapp" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-docs-webapp">tomcat-docs-webapp as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-el-3_0-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-el-3_0-api">tomcat-el-3_0-api as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-javadoc" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-javadoc">tomcat-javadoc as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-jsp-2_3-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-jsp-2_3-api">tomcat-jsp-2_3-api as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-lib" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-lib">tomcat-lib as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-servlet-3_1-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-servlet-3_1-api">tomcat-servlet-3_1-api as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-webapps" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:tomcat-webapps">tomcat-webapps as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat">tomcat as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-admin-webapps" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-admin-webapps">tomcat-admin-webapps as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-docs-webapp" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-docs-webapp">tomcat-docs-webapp as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-el-3_0-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-el-3_0-api">tomcat-el-3_0-api as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-javadoc" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-javadoc">tomcat-javadoc as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-jsp-2_3-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-jsp-2_3-api">tomcat-jsp-2_3-api as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-lib" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-lib">tomcat-lib as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-servlet-3_1-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-servlet-3_1-api">tomcat-servlet-3_1-api as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-webapps" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:tomcat-webapps">tomcat-webapps as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat">tomcat as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-admin-webapps" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-admin-webapps">tomcat-admin-webapps as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-docs-webapp" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-docs-webapp">tomcat-docs-webapp as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-el-2_2-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-el-2_2-api">tomcat-el-2_2-api as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-javadoc" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-javadoc">tomcat-javadoc as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-jsp-2_2-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-jsp-2_2-api">tomcat-jsp-2_2-api as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-lib" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-lib">tomcat-lib as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-servlet-3_0-api" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-servlet-3_0-api">tomcat-servlet-3_0-api as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="tomcat-webapps" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:tomcat-webapps">tomcat-webapps as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could result in the same Processor being used for multiple requests which in turn could lead to unexpected errors and/or response mix-up.</Note>
    </Notes>
    <CVE>CVE-2017-5651</CVE>
    <ProductStatuses>
      <Status Type="Known Not Affected">
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-admin-webapps</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-docs-webapp</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-el-3_0-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-javadoc</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-jsp-2_3-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-lib</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-servlet-3_1-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:tomcat-webapps</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-admin-webapps</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-docs-webapp</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-el-3_0-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-javadoc</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-jsp-2_3-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-lib</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-servlet-3_1-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:tomcat-webapps</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-admin-webapps</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-docs-webapp</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-el-2_2-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-javadoc</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-jsp-2_2-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-lib</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-servlet-3_0-api</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:tomcat-webapps</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>3.6</BaseScoreV2>
        <VectorV2>AV:N/AC:H/Au:S/C:P/I:P/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.8</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
