Skip to main content

CVE-2012-2733

Severity

5.3

Description

java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.

Mitigation

We recommend upgrading to a version of this component that is not vulnerable to this specific issue.

Project

Apache TomEE

Category
n/a
Tags
data
operational
Date Disclosed

2012-11-16

Date Discovered

2012-05-14

Apache TomEE 1.0.x

First release:
2012-04-27
0
Support Lifecycle:
Namespace:
javax
Feel Vulnerable? 

Contact us so we can help you.

* These fields are required.