Lucene search

K
f5F5F5:K17123
HistoryAug 13, 2015 - 12:00 a.m.

K17123 : Apache Tomcat vulnerability CVE-2014-0230

2015-08-1300:00:00
my.f5.com
26

5.5 Medium

AI Score

Confidence

High

0.073 Low

EPSS

Percentile

94.1%

Security Advisory Description

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts. (CVE-2014-0230)
Impact
An attacker may be able to cause a denial-of-service (DoS).
This vulnerability would require a locally authenticated user for BIG-IP and Enterprise Manager, which does not expose the Apache Tomcat process directly to network communications.