vendor:
Tomcat
by:
Oliver Karow
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Tomcat
Affected Version From: Apache Tomcat 4
Affected Version To: Apache Tomcat 4
Patch Exists: NO
Related CWE: N/A
CPE: a:apache:tomcat:4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Apache Tomcat 4 Remote Denial of Service Vulnerability
When certain non-HTTP request types are handled by the Tomcat HTTP connector, the Tomcat server will reject subsequent requests on the affected port until the service is restarted. A proof-of-concept exploit is available which sends a malicious request to the Tomcat Admin Port, causing the page to become inaccessible.
Mitigation:
Restrict access to the Tomcat Admin Port and ensure that all requests are valid HTTP requests.