PT-2009-2745 · Apache+2 · Apache Tomcat+2
Published
2009-06-03
·
Updated
2023-02-13
·
CVE-2009-0033
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 4.1.0 through 4.1.39
Apache Tomcat versions 5.5.0 through 5.5.27
Apache Tomcat versions 6.0.0 through 6.0.18
Description
The issue allows remote attackers to cause a denial of service, resulting in an application outage, by sending a crafted request with invalid headers via the Java AJP connector when mod jk load balancing is used. This can lead to temporary blocking of connectors that have encountered errors. For instance, an error can occur due to a malformed HTTP Host header. If the connector is part of a mod jk load balancing worker, it will be put into an error state and blocked from use for about one minute, which can be exploited for a denial of service attack using a carefully crafted request.
Recommendations
For Apache Tomcat versions 4.1.0 through 4.1.39, consider disabling the Java AJP connector until a patch is available to prevent exploitation.
For Apache Tomcat versions 5.5.0 through 5.5.27, restrict access to the mod jk load balancing worker to minimize the risk of denial of service attacks.
For Apache Tomcat versions 6.0.0 through 6.0.18, avoid using the Java AJP connector with mod jk load balancing until the issue is resolved.
Exploit
Fix
DoS
RCE
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Tomcat
Hp-Ux
Red Hat