CVE-2014-0095
Denial of service in Apache Tomcat
EPSS 9.7%
Description
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
How to fix CVE-2014-0095
To remediate CVE-2014-0095, upgrade the affected package to a fixed version below.
- Maven/org.apache.tomcat.embed:tomcat-embed-core—upgrade to 8.0.4 or later
- Maven/org.apache.tomcat:tomcat-coyote—upgrade to 8.0.4 or later
Is CVE-2014-0095 being exploited?
Moderate — EPSS is 9.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- >= 8.0.0-RC1, < 8.0.4
- >= 8.0.0-RC1, < 8.0.4