CVE-2014-0230

Description

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.901

Associated Vulnerability

VulnerabilityOS Platform
Update Tomcat to 9.5.14Windows
Update Tomcat to 9.5.5Windows
Update Tomcat to 9.5.7Windows
Update Tomcat to 9.5.8Windows
Update Tomcat to 9.6.10Windows
Update Tomcat to 9.6.3Windows
Update Tomcat to 9.6.4Windows
Update Tomcat to 9.6.7Windows
Update Tomcat to 9.6.8Windows
Update Tomcat to 2.4.5Windows
Update Tomcat to 3.0.14Windows
Vulnerabilities CVE-2014-0227,CVE-2014-0230 are fixed in Apache - tomcat 7.0.55Windows
Vulnerabilities CVE-2014-0227,CVE-2014-0230 are fixed in Apache - tomcat 8.0.9Windows
Vulnerabilities CVE-2014-0230,CVE-2014-7810 are fixed in Apache - tomcat 6.0.44Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2.6.5Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.4Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.0.6Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.0.2Windows
Servlet and JSP engine (USN-2654-1) libtomcat7-java_7.0.56-2ubuntu0.1_all.debLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-6.0.41-0.45.1.noarch.rpmLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-admin-webapps-6.0.41-0.45.1.noarch.rpmLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-docs-webapp-6.0.41-0.45.1.noarch.rpmLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-javadoc-6.0.41-0.45.1.noarch.rpmLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-jsp-2_1-api-6.0.41-0.45.1.noarch.rpmLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-lib-6.0.41-0.45.1.noarch.rpmLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-servlet-2_5-api-6.0.41-0.45.1.noarch.rpmLinux
SUSE-SU-2015:1337-1(SUSE Linux Enterprise Server 11 SP3 ) tomcat6-webapps-6.0.41-0.45.1.noarch.rpmLinux
Update Tomcat to 9.5.14 (For Linux)Linux
Update Tomcat to 9.5.5 (For Linux)Linux
Update Tomcat to 9.5.7 (For Linux)Linux
Update Tomcat to 9.5.8 (For Linux)Linux
Update Tomcat to 9.6.10 (For Linux)Linux
Update Tomcat to 9.6.3 (For Linux)Linux
Update Tomcat to 9.6.4 (For Linux)Linux
Update Tomcat to 9.6.7 (For Linux)Linux
Update Tomcat to 9.6.8 (For Linux)Linux
Update Tomcat to 2.4.5 (For Linux)Linux
Update Tomcat to 3.0.14 (For Linux)Linux
Vulnerabilities CVE-2014-0227,CVE-2014-0230 are fixed in Apache - tomcat for Linux 7.0.55Linux
Vulnerabilities CVE-2014-0227,CVE-2014-0230 are fixed in Apache - tomcat for Linux 8.0.9Linux
Vulnerabilities CVE-2014-0230,CVE-2014-7810 are fixed in Apache - tomcat for Linux 6.0.44Linux
CVE-2014-0230NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234