Korean
<< Back
VID 22497
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description According to its self-reported version number, the instance of Apache Tomcat 4.x listening on the remote host is earlier than 4.1.3 and, as such, may be affected by a denial of service vulnerability.
A malicious HTTP request can cause a request processing thread to become unresponsive. Further requests of this type can cause all request processing threads to become unresponsive.

* Note: This check solely relied on the version number of the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://tomcat.apache.org/security-4.html#Fixed_in_Apache_Tomcat_4.1.3
http://archives.neohapsis.com/archives/bugtraq/2002-06/0245.html

* Platforms Affected:
Apache Tomcat versions prior to 4.x < 4.1.3
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (4.1.3 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2002-0935 (CVE)
Related URL 5067 (SecurityFocus)
Related URL (ISS)