mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8261
https://issues.apache.org/bugzilla/show_bug.cgi?id=46949
https://exchange.xforce.ibmcloud.com/vulnerabilities/50059
http://www.vupen.com/english/advisories/2009/3184
http://www.vupen.com/english/advisories/2009/1147
http://www.ubuntu.com/usn/usn-787-1
http://www.securityfocus.com/bid/34663
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/PR46949.diff
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=766938&r2=767089
http://security.gentoo.org/glsa/glsa-200907-04.xml
http://secunia.com/advisories/35721