Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.170599
Category:Web Servers
Title:Apache Tomcat DoS Vulnerability (Oct 2023) - Windows
Summary:Apache Tomcat is prone to a denial of service (DoS); vulnerability.
Description:Summary:
Apache Tomcat is prone to a denial of service (DoS)
vulnerability.

Vulnerability Insight:
Tomcat's internal fork of a Commons FileUpload included an
unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web
application opened a stream for an uploaded file but failed to close the stream. The file would
never be deleted from disk creating the possibility of an eventual denial of service due to the disk
being full.

Affected Software/OS:
Apache Tomcat versions 8.5.85 through 8.5.93 and 9.0.70 through
9.0.80 on Windows only.

Solution:
Update to version 8.5.94, 9.0.81 or later.

CVSS Score:
5.4

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-42794
https://lists.apache.org/thread/vvbr2ms7lockj1hlhz5q3wmxb2mwcw82
http://www.openwall.com/lists/oss-security/2023/10/10/8
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.