5
CVSSv2

CVE-2014-0095

Published: 31/05/2014 Updated: 15/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x prior to 8.0.4 allows remote malicious users to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 8.0.1

apache tomcat 8.0.0

apache tomcat 8.0.3

Vendor Advisories

java/org/apache/coyote/ajp/AbstractAjpProcessorjava in Apache Tomcat 8x before 804 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing ...