Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2014-0227 | First vendor Publication | 2015-02-15 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.4 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0227 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-19 | Data Handling |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:29131 | |||
Oval ID: | oval:org.mitre.oval:def:29131 | ||
Title: | HP-UX Apache Tomcat v7.x, Remote Denial of Service (DoS) and Other Vulnerabilities | ||
Description: | java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2014-0227 | Version: | 3 |
Platform(s): | HP-UX 11 | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2015-07-16 | IAVM : 2015-A-0160 - Multiple Vulnerabilities in Oracle Linux and Virtualization Severity : Category I - VMSKEY : V0061123 |
Snort® IPS/IDS
Date | Description |
---|---|
2020-01-16 | Apache Tomcat chunked transfer encoding denial of service attempt RuleID : 52471 - Revision : 1 - Type : SERVER-APACHE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-03-28 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3530.nasl - Type : ACT_GATHER_INFO |
2016-01-19 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3447.nasl - Type : ACT_GATHER_INFO |
2015-09-16 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL16344.nasl - Type : ACT_GATHER_INFO |
2015-07-16 | Name : The application installed on the remote host is affected by multiple vulnerab... File : oracle_secure_global_desktop_jul_2015_cpu.nasl - Type : ACT_GATHER_INFO |
2015-06-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2655-1.nasl - Type : ACT_GATHER_INFO |
2015-06-26 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-2654-1.nasl - Type : ACT_GATHER_INFO |
2015-05-29 | Name : The remote Debian host is missing a security update. File : debian_DLA-232.nasl - Type : ACT_GATHER_INFO |
2015-05-18 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-527.nasl - Type : ACT_GATHER_INFO |
2015-05-18 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-526.nasl - Type : ACT_GATHER_INFO |
2015-05-18 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-525.nasl - Type : ACT_GATHER_INFO |
2015-05-14 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150512_tomcat_on_SL7_x.nasl - Type : ACT_GATHER_INFO |
2015-05-14 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20150512_tomcat6_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2015-05-13 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0991.nasl - Type : ACT_GATHER_INFO |
2015-05-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0991.nasl - Type : ACT_GATHER_INFO |
2015-05-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-0983.nasl - Type : ACT_GATHER_INFO |
2015-05-13 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-0983.nasl - Type : ACT_GATHER_INFO |
2015-05-13 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0991.nasl - Type : ACT_GATHER_INFO |
2015-05-13 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-0983.nasl - Type : ACT_GATHER_INFO |
2015-03-30 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-084.nasl - Type : ACT_GATHER_INFO |
2015-03-19 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-053.nasl - Type : ACT_GATHER_INFO |
2015-03-19 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2015-052.nasl - Type : ACT_GATHER_INFO |
2015-03-01 | Name : The remote Apache Tomcat server is affected by multiple denial of service vul... File : tomcat_8_0_9.nasl - Type : ACT_GATHER_INFO |
2015-03-01 | Name : The remote Apache Tomcat server is affected by a denial of service vulnerabil... File : tomcat_6_0_42.nasl - Type : ACT_GATHER_INFO |
2015-02-24 | Name : The remote Fedora host is missing a security update. File : fedora_2015-2109.nasl - Type : ACT_GATHER_INFO |
2014-09-02 | Name : The remote Apache Tomcat server is affected by multiple vulnerabilities. File : tomcat_7_0_55.nasl - Type : ACT_GATHER_INFO |
2014-08-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1088.nasl - Type : ACT_GATHER_INFO |
2014-08-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1087.nasl - Type : ACT_GATHER_INFO |
2014-08-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1019.nasl - Type : ACT_GATHER_INFO |
2014-08-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2014-1020.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 12:38:31 |
|
2023-11-07 21:44:58 |
|
2021-05-04 12:29:31 |
|
2021-04-22 01:35:43 |
|
2020-05-23 00:39:24 |
|
2019-04-15 21:18:58 |
|
2019-04-15 17:18:44 |
|
2019-03-25 17:18:58 |
|
2019-03-21 21:19:11 |
|
2019-03-18 12:02:23 |
|
2017-11-09 09:31:05 |
|
2017-09-22 09:24:09 |
|
2017-01-03 09:22:52 |
|
2016-12-31 09:24:20 |
|
2016-12-07 09:24:11 |
|
2016-10-26 09:22:42 |
|
2016-10-25 09:21:51 |
|
2016-08-23 09:24:49 |
|
2016-04-28 13:28:16 |
|
2016-04-26 13:27:45 |
|
2016-04-26 09:25:20 |
|
2016-03-29 13:21:00 |
|
2016-01-20 13:24:06 |
|
2015-10-18 17:22:26 |
|
2015-09-17 13:23:33 |
|
2015-09-02 13:39:08 |
|
2015-07-18 13:28:11 |
|
2015-07-17 09:19:19 |
|
2015-06-27 13:28:47 |
|
2015-05-30 13:27:34 |
|
2015-05-19 13:27:45 |
|
2015-05-15 13:28:58 |
|
2015-05-14 13:28:07 |
|
2015-04-07 09:26:46 |
|
2015-04-02 09:25:50 |
|
2015-03-31 13:28:15 |
|
2015-03-28 09:25:48 |
|
2015-03-26 09:26:16 |
|
2015-03-20 13:28:49 |
|
2015-03-18 09:26:24 |
|
2015-03-06 00:22:58 |
|
2015-03-03 09:23:09 |
|
2015-03-02 13:24:37 |
|
2015-02-25 13:24:05 |
|
2015-02-18 05:21:59 |
|
2015-02-16 05:21:56 |
|