CVE-2014-0095
published 2014-05-31CVE-2014-0095: java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
8.49%
94.5th percentile
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_apache5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
8: Denial of service via AJP requests with content length zero
vendor_redhat·2014-05-30·CVSS 5.0
CVE-2014-0095 [MEDIUM] CWE-130 8: Denial of service via AJP requests with content length zero
8: Denial of service via AJP requests with content length zero
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
Statement: This flaw does not affect Apache Tomcat as shipped by any Red Hat product as it was introduced in Apache Tomcat 8.0.0-RC2 and did not affect earlier versions.
Package: tomcat5 (Red Hat Enterprise Linux 5) - Not affected
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
Package: tomcat (Red Hat Enterprise Linux 7) - Not affected
Package: tomcat5 (Red Hat JBoss Enterprise Web Server 1) - Not affected
Package: tomcat6 (Red Hat JBoss Enterprise Web Server 1) - No
Apache
Apache tomcat: CVE-2014-0095
vendor_apache·CVSS 5.0
CVE-2014-0095 [MEDIUM] Apache tomcat: CVE-2014-0095
Apache tomcat: CVE-2014-0095
A regression was introduced in 1519838 that caused AJP requests to hang if an explicit content length of zero was set on the request. The hanging request consumed a request processing thread which could lead to a denial of service. This was fixed in revision 1578392 . This issue was reported as a possible bug via the Tomcat users mailing list on 3 March 2014 and the security implications were identified by the Tomcat security team on the same day. This issue was made public on 27 May 2014. Affects: 8.0.0-RC2 to 8.0.3 Important: Information disclosure
OSV
Denial of service in Apache Tomcat
osv·2022-05-17
CVE-2014-0095 [MEDIUM] Denial of service in Apache Tomcat
Denial of service in Apache Tomcat
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
GHSA
Denial of service in Apache Tomcat
ghsa·2022-05-17
CVE-2014-0095 [MEDIUM] CWE-20 Denial of service in Apache Tomcat
Denial of service in Apache Tomcat
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
No detection rules found.
No public exploits indexed.
http://seclists.org/fulldisclosure/2014/May/134http://secunia.com/advisories/59873http://secunia.com/advisories/60729http://svn.apache.org/viewvc?view=revision&revision=1578392http://tomcat.apache.org/security-8.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21678231http://www-01.ibm.com/support/docview.wss?uid=swg21681528http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.securityfocus.com/bid/67673http://www.securitytracker.com/id/1030300http://seclists.org/fulldisclosure/2014/May/134http://secunia.com/advisories/59873http://secunia.com/advisories/60729http://svn.apache.org/viewvc?view=revision&revision=1578392http://tomcat.apache.org/security-8.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21678231http://www-01.ibm.com/support/docview.wss?uid=swg21681528http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.securityfocus.com/bid/67673http://www.securitytracker.com/id/1030300
2014-05-31
Published