Lucene search

K
kasperskyKaspersky LabKLA10072
HistoryMar 30, 2014 - 12:00 a.m.

KLA10072 Multiple vulnerabilities in Apache Tomcat

2014-03-3000:00:00
Kaspersky Lab
threats.kaspersky.com
41

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

9.1 High

AI Score

Confidence

High

0.038 Low

EPSS

Percentile

92.0%

Multiple serious vulnerabilities have been found in Apache Tomcat. Malicious users can exploit these vulnerabilities to cause denial of service, bypass security restrictions and read arbitrary files. Below is a complete list of vulnerabilities

  1. An integer overflow vulnerability can be exploited remotely via a specially designed request streaming or a specially designed HTTP header;
  2. An improper XSLT restriction vulnerability can be exploited remotely via a specially designed web application;

Original advisories

Apache bulletin

Related products

Apache-Tomcat

CVE list

CVE-2014-0075 critical

CVE-2014-0096 warning

CVE-2014-0099 warning

Solution

Update to latest version

Impacts

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • RLF

Read Local Files. Exploitation of vulnerabilities with this impact can lead to reading some inaccessible files. Files that can be read depends on conсrete program errors.

Affected Products

  • Apache Tomcat 7 versions 7.0.52 and earlier

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

9.1 High

AI Score

Confidence

High

0.038 Low

EPSS

Percentile

92.0%