Resource management error in Apache Tomcat - CVE-2014-0230

 

Resource management error in Apache Tomcat - CVE-2014-0230

Published: June 22, 2022


Vulnerability identifier: #VU64581
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0230
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to Apache Tomcat does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body. A remote attacker can cause a denial of service (thread consumption) via a series of aborted upload attempts.


Affected software

Apache Tomcat
Dell Secure Connect Gateway
Fedora
OpenVMS CSWS_Java
FlashSystem 840 9840-AE1 & 9843-AE1
tomcat
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
IBM SAN Volume Controller

How to mitigate CVE-2014-0230

Install updates from vendor's website.

Apache Tomcat - addressed in versions 6.0.44, 7.0.55, 8.0.9
Dell Secure Connect Gateway - update to 5.12.00.10
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.3.8
tomcat - update to 7.0.65-1.el6
IBM Storwize V3500 - addressed in versions 7.3.0.10, 7.4.0.5, 7.5.0.2
IBM Storwize V3700 - addressed in versions 7.3.0.10, 7.4.0.5, 7.5.0.2
IBM Storwize V5000 - addressed in versions 7.3.0.10, 7.4.0.5, 7.5.0.2
IBM Storwize V7000 - addressed in versions 7.3.0.10, 7.4.0.5, 7.5.0.2
IBM SAN Volume Controller - addressed in versions 7.3.0.10, 7.4.0.5, 7.5.0.2

External References

Related Security Bulletins