Korean
<< Back
VID 210246
Severity 40
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The version of Tomcat installed on the remote host is prior to 8.5.88. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_8.5.88_security-8 advisory.

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87.
If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

* References:
https://github.com/apache/tomcat/commit/5badf94e79e5de206fc0ef3054fd536b1bb787cd
https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.88

* Platforms Affected:
Apache Tomcat Server versions 8.5.x prior to 8.5.88
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (8.5.88 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2023-28709 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)