| Vulnerability Name: | CVE-2023-28709 (CCN-255893) | ||||||||||||
| Assigned: | 2023-05-22 | ||||||||||||
| Published: | 2023-05-22 | ||||||||||||
| Updated: | 2023-06-16 | ||||||||||||
| Summary: | Apache Tomcat is vulnerable to a denial of service, caused by an incomplete fix for CVE-2023-24998 related to the failure to limit the number of request parts to be processed in the file upload function. By sending a specially crafted request using query string parameters, a remote attacker could exploit this vulnerability to cause a denial of service. | ||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2023-28709 Source: security@apache.org Type: Mailing List, Third Party Advisory security@apache.org Source: XF Type: UNKNOWN apache-cve202328709-dos(255893) Source: CCN Type: Apache Mailing List, Monday, May 22, 2023 6:01:20 AM EDT [SECURITY] CVE-2023-28709 Apache Tomcat - Fix for CVE-2023-24998 was incomplete Source: security@apache.org Type: Mailing List, Vendor Advisory security@apache.org Source: security@apache.org Type: UNKNOWN security@apache.org Source: security@apache.org Type: UNKNOWN security@apache.org Source: CCN Type: IBM Security Bulletin 7001721 (Security SOAR) IBM Security SOAR is using a component with known vulnerabilities (CVE-2023-28709) Source: CCN Type: IBM Security Bulletin 7005499 (Power HMC) Vulnerability in Apache Tomcat Server (CVE-2023-28709 ) affects Power HMC Source: CCN Type: IBM Security Bulletin 7006099 (Integration Bus) IBM Integration Bus is vulnerable to a denial of service due to Apache Tomcat (CVE-2023-28709) Source: CCN Type: IBM Security Bulletin 7010061 (App Connect Professional) Multiple vulnerabilities in Apache Tomcat affects App Connect Professional. Source: CCN Type: IBM Security Bulletin 7011435 (UrbanCode Deploy) IBM UrbanCode Deploy (UCD) is vulnerable to denial of service due to Apache Tomcat (CVE-2023-28709) | ||||||||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||