CVE-2014-0095
Last modified
CVE-2014-0095 is a vulnerability of currently unknown severity. java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.. EPSS estimates a 8.49% chance of exploitation in the next 30 days.
Description
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Tomcat | 8.0.0 | Rc1 |
| Apache | Tomcat | 8.0.1 | — |
| Apache | Tomcat | 8.0.3 | — |
References
- http://tomcat.apache.org/security-8.htmlVendor Advisory
- http://tomcat.apache.org/security-8.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0095?
How severe is CVE-2014-0095?
How do I fix CVE-2014-0095?
Are you affected by CVE-2014-0095?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
