The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | apache-tomcat-upgrade-8_5_8apache-tomcat-upgrade-9_0_0apache-tomcat-8_5apache-tomcat-9_0apache-tomcat-upgrade-latest | Aug 10, 2017 | Aug 10, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-web-java-servlet-tomcat-8-8-5-9-0-175-3-16-0-3-0oracle-solaris-11-3-upgrade-web-java-servlet-tomcat-8-tomcat-admin-8-5-9-0-175-3-16-0-3-0oracle-solaris-11-3-upgrade-web-java-servlet-tomcat-8-tomcat-examples-8-5-9-0-175-3-16-0-3-0 | May 29, 2017 | May 29, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub