Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-0033


Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.


Published

2009-06-05T16:00:00.187

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache tomcat 4.1.0 Yes
Application apache tomcat 4.1.1 Yes
Application apache tomcat 4.1.2 Yes
Application apache tomcat 4.1.3 Yes
Application apache tomcat 4.1.3 Yes
Application apache tomcat 4.1.4 Yes
Application apache tomcat 4.1.5 Yes
Application apache tomcat 4.1.6 Yes
Application apache tomcat 4.1.7 Yes
Application apache tomcat 4.1.8 Yes
Application apache tomcat 4.1.9 Yes
Application apache tomcat 4.1.9 Yes
Application apache tomcat 4.1.10 Yes
Application apache tomcat 4.1.11 Yes
Application apache tomcat 4.1.12 Yes
Application apache tomcat 4.1.13 Yes
Application apache tomcat 4.1.14 Yes
Application apache tomcat 4.1.15 Yes
Application apache tomcat 4.1.16 Yes
Application apache tomcat 4.1.17 Yes
Application apache tomcat 4.1.18 Yes
Application apache tomcat 4.1.19 Yes
Application apache tomcat 4.1.20 Yes
Application apache tomcat 4.1.21 Yes
Application apache tomcat 4.1.22 Yes
Application apache tomcat 4.1.23 Yes
Application apache tomcat 4.1.24 Yes
Application apache tomcat 4.1.25 Yes
Application apache tomcat 4.1.26 Yes
Application apache tomcat 4.1.27 Yes
Application apache tomcat 4.1.28 Yes
Application apache tomcat 4.1.29 Yes
Application apache tomcat 4.1.30 Yes
Application apache tomcat 4.1.31 Yes
Application apache tomcat 4.1.32 Yes
Application apache tomcat 4.1.33 Yes
Application apache tomcat 4.1.34 Yes
Application apache tomcat 4.1.35 Yes
Application apache tomcat 4.1.36 Yes
Application apache tomcat 4.1.37 Yes
Application apache tomcat 4.1.38 Yes
Application apache tomcat 4.1.39 Yes
Application apache tomcat 5.5.0 Yes
Application apache tomcat 5.5.1 Yes
Application apache tomcat 5.5.2 Yes
Application apache tomcat 5.5.3 Yes
Application apache tomcat 5.5.4 Yes
Application apache tomcat 5.5.5 Yes
Application apache tomcat 5.5.6 Yes
Application apache tomcat 5.5.7 Yes
Application apache tomcat 5.5.8 Yes
Application apache tomcat 5.5.9 Yes
Application apache tomcat 5.5.10 Yes
Application apache tomcat 5.5.11 Yes
Application apache tomcat 5.5.12 Yes
Application apache tomcat 5.5.13 Yes
Application apache tomcat 5.5.14 Yes
Application apache tomcat 5.5.15 Yes
Application apache tomcat 5.5.16 Yes
Application apache tomcat 5.5.17 Yes
Application apache tomcat 5.5.18 Yes
Application apache tomcat 5.5.19 Yes
Application apache tomcat 5.5.20 Yes
Application apache tomcat 5.5.21 Yes
Application apache tomcat 5.5.22 Yes
Application apache tomcat 5.5.23 Yes
Application apache tomcat 5.5.24 Yes
Application apache tomcat 5.5.25 Yes
Application apache tomcat 5.5.26 Yes
Application apache tomcat 5.5.27 Yes
Application apache tomcat 6.0.0 Yes
Application apache tomcat 6.0.1 Yes
Application apache tomcat 6.0.2 Yes
Application apache tomcat 6.0.3 Yes
Application apache tomcat 6.0.4 Yes
Application apache tomcat 6.0.5 Yes
Application apache tomcat 6.0.6 Yes
Application apache tomcat 6.0.7 Yes
Application apache tomcat 6.0.8 Yes
Application apache tomcat 6.0.9 Yes
Application apache tomcat 6.0.10 Yes
Application apache tomcat 6.0.11 Yes
Application apache tomcat 6.0.12 Yes
Application apache tomcat 6.0.13 Yes
Application apache tomcat 6.0.14 Yes
Application apache tomcat 6.0.15 Yes
Application apache tomcat 6.0.16 Yes

References