Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 7.0.55Upgrade Apache Tomcat to 8.0.9Upgrade Apache Tomcat to 6.0.44 | Jun 7, 2015 | Jun 7, 2015 |
| Debian | — | Upgrade tomcat6 | Mar 28, 2016 | Jun 7, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 13, 2015 |
| Freebsd | — | Upgrade hadoop2Upgrade tomcat7Upgrade oozieUpgrade tomcat8Upgrade tomcat | Dec 10, 2025 | Jun 16, 2015 |
| Hpux | — | Update hpuxws22Tomcat.hpuxws22TOMCAT.TOMCAT to the latest version | Aug 11, 2017 | Jun 7, 2015 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat/tomcat-examples to version 6.0.44-0.175.2.15.0.3.0 on Solaris 11.2Upgrade web/java-servlet/tomcat to version 6.0.44-0.175.2.15.0.3.0 on Solaris 11.2Upgrade web/java-servlet/tomcat/tomcat-examples to version 6.0.44-0.175.3.1.0.2.0 on Solaris 11.3Upgrade web/java-servlet/tomcat to version 6.0.44-0.175.3.1.0.2.0 on Solaris 11.3 | May 29, 2017 | Jun 7, 2015 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jul 19, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 19, 2014 |
| Suse | — | Upgrade tomcat6-jsp-2_1-apiUpgrade tomcat6-libUpgrade tomcat6-admin-webappsUpgrade tomcat6-javadocUpgrade tomcat6-servlet-2_5-apiUpgrade tomcat6-docs-webappUpgrade tomcat6-webappsUpgrade tomcat6 | Dec 18, 2015 | Jun 7, 2015 |
| Ubuntu | — | Upgrade libtomcat7-javaUpgrade libtomcat6-java | Nov 8, 2024 | Jun 7, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub