Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.802682
Kategorie:Web Servers
Titel:Apache Tomcat Partial HTTP Requests DoS Vulnerability - Windows
Zusammenfassung:Apache Tomcat Server is prone to a denial of service (DoS) vulnerability.;; This VT has been deprecated for the reasons explained by the Apache Tomcat team in the references.
Beschreibung:Summary:
Apache Tomcat Server is prone to a denial of service (DoS) vulnerability.

This VT has been deprecated for the reasons explained by the Apache Tomcat team in the references.

Vulnerability Insight:
The flaw is caused by configuring an appropriate timeout using
the connectionTimeout property for the relevant Connector(s) defined in server.xml.

Vulnerability Impact:
Successful exploitation will allow remote attackers to cause
a denial of service conditions.

Affected Software/OS:
Apache Tomcat version 7.0.x.

Solution:
Update to Apache Tomcat 7.0.52 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-5568
56686
http://www.securityfocus.com/bid/56686
[oss-security] 20121125 Re: CVE Request: slowloris for tomcat
http://openwall.com/lists/oss-security/2012/11/26/2
[users] 20090619 How does Tomcat handle a slow HTTP DoS?
http://tomcat.10.n6.nabble.com/How-does-Tomcat-handle-a-slow-HTTP-DoS-tc2147776.html
[users] 20090620 Re: How does Tomcat handle a slow HTTP DoS?
http://tomcat.10.n6.nabble.com/How-does-Tomcat-handle-a-slow-HTTP-DoS-tc2147779.html
apache-tomcat-slowloris-dos(80317)
https://exchange.xforce.ibmcloud.com/vulnerabilities/80317
http://captainholly.wordpress.com/2009/06/19/slowloris-vs-tomcat/
https://bugzilla.redhat.com/show_bug.cgi?id=880011
openSUSE-SU-2012:1700
http://lists.opensuse.org/opensuse-updates/2012-12/msg00089.html
openSUSE-SU-2012:1701
http://lists.opensuse.org/opensuse-updates/2012-12/msg00090.html
openSUSE-SU-2013:0147
http://lists.opensuse.org/opensuse-updates/2013-01/msg00037.html
CopyrightCopyright (C) 2012 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.