Skip to content

Jakarta Tomcat Denial of Service vulnerability

Moderate severity GitHub Reviewed Published Apr 29, 2022 to the GitHub Advisory Database • Updated Sep 18, 2023

Package

maven org.apache.tomcat:tomcat (Maven)

Affected versions

< 3.3.1a

Patched versions

3.3.1a

Description

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

References

Published by the National Vulnerability Database Feb 7, 2003
Published to the GitHub Advisory Database Apr 29, 2022
Reviewed Sep 18, 2023
Last updated Sep 18, 2023

Severity

Moderate

EPSS score

0.352%
(73rd percentile)

Weaknesses

CVE ID

CVE-2003-0045

GHSA ID

GHSA-w97x-xfxf-f9xj

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.