CVE-2023-28709
published 2023-05-22CVE-2023-28709: The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default…
PriorityP357high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
51.55%
98.8th percentile
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | 10.1.5 – 10.1.7 | — |
| apache | tomcat | 8.5.85 – 8.5.87 | — |
| apache | tomcat | 9.0.71 – 9.0.73 | — |
| debian | debian_linux | — | — |
| debian | tomcat10 | < tomcat10 10.1.6-1+deb12u1 (bookworm) | tomcat10 10.1.6-1+deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.6-1+deb12u1 (bookworm) | tomcat10 10.1.6-1+deb12u1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets Apache Tomcat multipart/form-data upload endpoint when maxParameterCount is exhausted via query string parameters — monitor for requests that supply exactly maxParameterCount query string parameters combined with a multipart upload body, which may indicate an attempt to bypass the upload-parts limit and trigger DoS. ↗
- →Exploitation requires non-default HTTP connector configuration (maxParameterCount tuned down or otherwise reachable via query string alone); instances using default Tomcat connector settings are not exploitable — focus detection on non-default deployments. ↗
- →Attack vector is remote over HTTP; no authentication is required — prioritize monitoring of public-facing Tomcat HTTP connectors on affected versions (8.5.85–8.5.87, 9.0.71–9.0.73, 10.1.5–10.1.7, 11.0.0-M2–11.0.0-M4) for anomalous multipart upload traffic. ↗
- ·Vulnerability is only exploitable when non-default HTTP connector settings allow maxParameterCount to be reached purely via query string parameters; default Tomcat configurations are not affected. ↗
- ·Red Hat states no mitigation meeting their usability/stability standards is currently available; patching to a fixed version is the only remediation path. ↗
- ·pki-servlet-engine has been obsoleted in RHEL 8.9 and later by Tomcat; no additional fixes for the engine will be made available on that platform. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
osv·2023-07-06·CVSS 7.5
CVE-2023-28709 [HIGH] Apache Tomcat - Fix for CVE-2023-24998 was incomplete
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
GHSA
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
ghsa·2023-07-06·CVSS 7.5
CVE-2023-28709 [HIGH] CWE-193 Apache Tomcat - Fix for CVE-2023-24998 was incomplete
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
OSV
CVE-2023-28709: The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11
osv·2023-05-22·CVSS 7.5
CVE-2023-28709 [HIGH] CVE-2023-28709: The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench, Endeca Application Controller, Content Acquisition System (Apache Tomcat) — CVE-2023-28709
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2023-28709 [HIGH] Oracle Oracle Commerce Risk Matrix: Workbench, Endeca Application Controller, Content Acquisition System (Apache Tomcat) — CVE-2023-28709
Oracle Oracle Commerce Risk Matrix: Workbench, Endeca Application Controller, Content Acquisition System (Apache Tomcat) vulnerability
CVE: CVE-2023-28709
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) — CVE-2023-28709
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2023-28709 [HIGH] Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) — CVE-2023-28709
Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) vulnerability
CVE: CVE-2023-28709
CVSS: 7.5
Protocol: XMPP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Red Hat
tomcat: Fix for CVE-2023-24998 was incomplete
vendor_redhat·2023-05-22·CVSS 7.5
CVE-2023-28709 [HIGH] CWE-193 tomcat: Fix for CVE-2023-24998 was incomplete
tomcat: Fix for CVE-2023-24998 was incomplete
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
A vulnerability has been identified in Apache Tomcat due to an incomplete fix for CVE-2023-24998, which aims to limit the uploaded request parts that can be bypassed in a request. This issue may allow an attacker to use a malicious upload or series of uploads to cause a cras
Debian
CVE-2023-28709: tomcat10 - The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-...
vendor_debian·2023·CVSS 7.5
CVE-2023-28709 [HIGH] CVE-2023-28709: tomcat10 - The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-...
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
Scope: local
bookworm: resolved (fixed in 10.1.6-1+deb12u1)
forky: resolved (fixed in 10.1.10-1)
sid: resolved (fixed in 10.1.10-1)
trixie: resolved (fixed in 10.1.10-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/05/22/1https://lists.apache.org/thread/7wvxonzwb7k9hx9jt3q33cmy7j97jo3jhttps://security.gentoo.org/glsa/202305-37https://security.netapp.com/advisory/ntap-20230616-0004/https://www.debian.org/security/2023/dsa-5521http://www.openwall.com/lists/oss-security/2023/05/22/1https://lists.apache.org/thread/7wvxonzwb7k9hx9jt3q33cmy7j97jo3jhttps://security.gentoo.org/glsa/202305-37https://security.netapp.com/advisory/ntap-20230616-0004/https://www.debian.org/security/2023/dsa-5521
2023-05-22
Published