- Description
- java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
- Source
- secalert@redhat.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
- nvd@nist.gov
- CWE-20
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:tomcat:8.0.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4752862B-7D26-4285-B8A0-CF082C758353"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:8.0.0:rc10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58EA7199-3373-4F97-9907-3A479A02155E"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:8.0.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4693BD36-E522-4C8E-9667-8F3E14A05EF3"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:8.0.0:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BBBC5EA-012C-4C5D-A61B-BAF134B300DA"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:8.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A358FDF-C249-4D7A-9445-8B9E7D9D40AF"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:8.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFF96F96-34DB-4EB3-BF59-11220673FA26"
}
],
"operator": "OR"
}
]
}
]