Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25888
HistoryJul 15, 2020 - 7:48 a.m.

Denial Of Service (DoS)

2020-07-1507:48:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.912 High

EPSS

Percentile

98.9%

apache tomcat is vulnerable to denial of service. The HTTP/1.1 processor is not released after an upgrade to HTTP/2, allowing an attacker to cause a denial of service condition due to an OutOfMemoryException by sending a large number of upgrade requests.

References