The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat
allows remote attackers to obtain sensitive information via an
arbitrary request from an HTTP client, in opportunistic circumstances
involving (1) a request from a different client that included a
Content-Length header but no POST data or (2) a rapid series of
requests, related to noncompliance with the AJP protocol's
requirements for requests containing Content-Length headers.