QID 150688

Date Published: 2023-05-29

QID 150688: Apache Tomcat Denial Of Service (DoS) Vulnerability (CVE-2023-28709)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

Affected Products:
Apache Tomcat from version 8.5.85 to 8.5.87
Apache Tomcat from version 9.0.71 to 9.0.73
Apache Tomcat from version 10.1.5 to 10.1.7
Apache Tomcat from version 11.0.0-M2 to 11.0.0-M4

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.

Successful exploitation of the vulnerability can allow an attacker to trigger a DoS via malicious upload or series of uploads

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Upgrade to the Apache Tomcat to the latest version of Apache Tomcat. Please refer to Apache Tomcat 8 Security, Apache Tomcat 9 Security, Apache Tomcat 10 Security, Apache Tomcat 11 Security.

    CVEs related to QID 150688

    Software Advisories
    Advisory ID Software Component Link
    Apache Downloads URL Logo tomcat.apache.org/whichversion.html