Allocation of Resources Without Limits or Throttling in Apache Tomcat - CVE-2023-28709
Published: May 22, 2023
Vulnerability identifier: #VU76417
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28709
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an incomplete fox for #VU72427 (CVE-2023-24998). If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed. A remote attacker can initiate a series of uploads and perform a denial of service (DoS) attack.Affected software
Apache Tomcat
JBoss Web Server
Confluence Server
Amazon Linux AMI
Debian Linux
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Web and Scripting Module
openSUSE Leap
openEuler
IBM Integration Bus
IBM Rational Build Forge
Bamboo Server
IBM UrbanCode Release
UCD - IBM UrbanCode Deploy
Confluence Data Center
IBM Power Hardware Management Console (HMC)
NetWorker
IBM Data Risk Manager
SecureTransport
IBM Qradar SIEM
IBM App Connect Professional
MySQL Enterprise Monitor
Oracle Communications Instant Messaging Server
Oracle Commerce Guided Search
Tomcat
jws5-tomcat-native (Red Hat package)
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-jsp-2_3-api
tomcat
tomcat-webapps
tomcat-el-3_0-api
tomcat-servlet-3_1-api
tomcat-lib
tomcat-javadoc
tomcat8
tomcat-help
tomcat-jsvc
tomcat-servlet-4_0-api
jws5-tomcat (Red Hat package)
tomcat (Red Hat package)
tomcat-servlet-4.0-api
tomcat-jsp-2.3-api
tomcat-el-3.0-api
tomcat9
tomcat-embed
tomcat10 (Debian package)
www-servers/tomcat
Storage Copy Data Management
UrbanCode Build
Index Engines CyberSense
Dell Data Protection Central
IBM Security SOAR
JBoss Web Server
Confluence Server
Amazon Linux AMI
Debian Linux
Gentoo Linux
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Web and Scripting Module
openSUSE Leap
openEuler
IBM Integration Bus
IBM Rational Build Forge
Bamboo Server
IBM UrbanCode Release
UCD - IBM UrbanCode Deploy
Confluence Data Center
IBM Power Hardware Management Console (HMC)
NetWorker
IBM Data Risk Manager
SecureTransport
IBM Qradar SIEM
IBM App Connect Professional
MySQL Enterprise Monitor
Oracle Communications Instant Messaging Server
Oracle Commerce Guided Search
Tomcat
jws5-tomcat-native (Red Hat package)
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-jsp-2_3-api
tomcat
tomcat-webapps
tomcat-el-3_0-api
tomcat-servlet-3_1-api
tomcat-lib
tomcat-javadoc
tomcat8
tomcat-help
tomcat-jsvc
tomcat-servlet-4_0-api
jws5-tomcat (Red Hat package)
tomcat (Red Hat package)
tomcat-servlet-4.0-api
tomcat-jsp-2.3-api
tomcat-el-3.0-api
tomcat9
tomcat-embed
tomcat10 (Debian package)
www-servers/tomcat
Storage Copy Data Management
UrbanCode Build
Index Engines CyberSense
Dell Data Protection Central
IBM Security SOAR
How to mitigate CVE-2023-28709
Install updates from vendor's website.
Apache Tomcat - addressed in versions 8.5.88, 9.0.74, 10.1.8, 11.0.0-M5
IBM Data Risk Manager - update to 2.0.6.18
SecureTransport - update to 5.5-20230629
JBoss Web Server - update to 5.7.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Rational Build Forge - update to 8.0.0.24
Bamboo Server - addressed in versions 9.2.4, 9.3.1
Tomcat - update to D.9.0.87.01
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-15.redhat_15.el7jws, 1.2.31-15.redhat_15.el8jws, 1.2.31-15.redhat_15.el9jws
Storage Copy Data Management - update to 2.2.23.0
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.21, 7.0.5.16, 7.1.2.12, 7.2.3.5, 7.3.2.0
Confluence Data Center - addressed in versions 7.13.19, 7.19.11, 8.4.1
Confluence Server - addressed in versions 7.13.19, 7.19.11, 8.4.1
tomcat-admin-webapps - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-docs-webapp - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.75-150200.41.1
tomcat-jsp-2_3-api - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-webapps - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-el-3_0-api - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-servlet-3_1-api - update to 8.0.53-29.66.1
tomcat-lib - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-javadoc - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.75-150200.41.1
Index Engines CyberSense - update to 8.3
tomcat8 - update to 8.5.89-1.93
tomcat-help - update to 9.0.10-31
tomcat-jsvc - update to 9.0.10-31
tomcat - update to 9.0.10-31
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-15.redhat_00013.1.el7jws, 9.0.62-15.redhat_00013.1.el8jws, 9.0.62-15.redhat_00013.1.el9jws
tomcat (Red Hat package) - addressed in versions 9.0.62-27.el8_9, 9.0.62-37.el9_3
tomcat-servlet-4.0-api - update to 9.0.62-30
tomcat-lib - update to 9.0.62-30
tomcat-jsp-2.3-api - update to 9.0.62-30
tomcat-el-3.0-api - update to 9.0.62-30
tomcat-docs-webapp - update to 9.0.62-30
tomcat-admin-webapps - update to 9.0.62-30
tomcat - update to 9.0.62-30
tomcat-webapps - update to 9.0.62-30
tomcat9 - update to 9.0.71-1
tomcat-embed - update to 9.0.75-150200.41.1
tomcat-jsvc - update to 9.0.75-150200.41.1
tomcat10 (Debian package) - update to 10.1.6-1+deb12u1
www-servers/tomcat - update to 10.1.8
IBM Power Hardware Management Console (HMC) - addressed in versions 10.1.1020.0 SP1, 10.2.1040.0
NetWorker - update to 19.9.0.2
Dell Data Protection Central - update to 19.10.0-4
IBM Security SOAR - update to 49.1
IBM Data Risk Manager - update to 2.0.6.18
SecureTransport - update to 5.5-20230629
JBoss Web Server - update to 5.7.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
IBM Rational Build Forge - update to 8.0.0.24
Bamboo Server - addressed in versions 9.2.4, 9.3.1
Tomcat - update to D.9.0.87.01
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-15.redhat_15.el7jws, 1.2.31-15.redhat_15.el8jws, 1.2.31-15.redhat_15.el9jws
Storage Copy Data Management - update to 2.2.23.0
UrbanCode Build - update to 6.1.7.10
IBM UrbanCode Release - update to 6.2.5.11
UCD - IBM UrbanCode Deploy - addressed in versions 6.2.7.21, 7.0.5.16, 7.1.2.12, 7.2.3.5, 7.3.2.0
Confluence Data Center - addressed in versions 7.13.19, 7.19.11, 8.4.1
Confluence Server - addressed in versions 7.13.19, 7.19.11, 8.4.1
tomcat-admin-webapps - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-docs-webapp - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.75-150200.41.1
tomcat-jsp-2_3-api - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-webapps - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-el-3_0-api - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-servlet-3_1-api - update to 8.0.53-29.66.1
tomcat-lib - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
tomcat-javadoc - addressed in versions 8.0.53-29.66.1, 9.0.36-3.105.1, 9.0.75-150200.41.1
Index Engines CyberSense - update to 8.3
tomcat8 - update to 8.5.89-1.93
tomcat-help - update to 9.0.10-31
tomcat-jsvc - update to 9.0.10-31
tomcat - update to 9.0.10-31
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.105.1, 9.0.36-150100.4.93.1, 9.0.75-150200.41.1
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-15.redhat_00013.1.el7jws, 9.0.62-15.redhat_00013.1.el8jws, 9.0.62-15.redhat_00013.1.el9jws
tomcat (Red Hat package) - addressed in versions 9.0.62-27.el8_9, 9.0.62-37.el9_3
tomcat-servlet-4.0-api - update to 9.0.62-30
tomcat-lib - update to 9.0.62-30
tomcat-jsp-2.3-api - update to 9.0.62-30
tomcat-el-3.0-api - update to 9.0.62-30
tomcat-docs-webapp - update to 9.0.62-30
tomcat-admin-webapps - update to 9.0.62-30
tomcat - update to 9.0.62-30
tomcat-webapps - update to 9.0.62-30
tomcat9 - update to 9.0.71-1
tomcat-embed - update to 9.0.75-150200.41.1
tomcat-jsvc - update to 9.0.75-150200.41.1
tomcat10 (Debian package) - update to 10.1.6-1+deb12u1
www-servers/tomcat - update to 10.1.8
IBM Power Hardware Management Console (HMC) - addressed in versions 10.1.1020.0 SP1, 10.2.1040.0
NetWorker - update to 19.9.0.2
Dell Data Protection Central - update to 19.10.0-4
IBM Security SOAR - update to 49.1
External References
Related Security Bulletins
- Denial of service in Apache Tomcat
- Gentoo update for Apache Tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- Allocation of resources without limits or throttling in IBM Power Hardware Management Console (HMC)
- Multiple vulnerabilities in IBM Integration Bus
- Multiple vulnerabilities in IBM Security SOAR
- Allocation of resources without limits or throttling in IBM App connect professional
- Allocation of resources without limits or throttling in IBM UrbanCode Deploy (UCD)
- Multiple vulnerabilities in Axway SecureTransport
- Allocation of Resources Without Limits or Throttling in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Amazon Linux AMI update for tomcat8
- Multiple vulnerabilities in Dell Index Engines CyberSense
- Confluence Server and Data Center update for Tomcat
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Red Hat JBoss Web Server 5.7
- Multiple vulnerabilities in JBoss Enterprise Web Server 5 for RHEL 8
- Multiple vulnerabilities in IBM Data Risk Manager
- Multiple vulnerabilities in Atlassian Bamboo Data Center and Server
- Multiple vulnerabilities in Dell NetWorker
- Debian update for tomcat10
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in IBM UrbanCode Release
- Multiple vulnerabilities in IBM UrbanCode Build
- Multiple vulnerabilities in IBM Rational Build Forge
- Red Hat Enterprise Linux 9 update for tomcat
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 8 update for tomcat
- Dell Data Protection Central update for third-party components
- openEuler update for tomcat
- Multiple vulnerabilities in IBM Storage Copy Data Management
- HP-UX update for Tomcat
- Amazon Linux AMI update for tomcat9
- Anolis OS update for tomcat