Apache Tomcat Denial of Service Vulnerability in Servlet and JSP Engine
CVE-2017-6056

7.5HIGH

Key Information:

Vendor
Canonical
Vendor
CVE Published:
17 February 2017

Summary

A programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine can lead to a denial of service condition. This vulnerability stems from a failure to backport a crucial fix during a previous patch implementation, resulting in an infinite loop which can easily be exploited. Affected versions include certain Debian distributions prior to 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7, as well as various Ubuntu versions. Organizations using these distributions are advised to update their systems to mitigate the risk.

References

EPSS Score

15% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.