Логотип exploitDog
bind:"BDU:2023-06729" OR bind:"CVE-2023-42794"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2023-06729" OR bind:"CVE-2023-42794"

Количество 10

Количество 10

fstec логотип

BDU:2023-06729

больше 2 лет назад

Уязвимость компонента Commons FileUpload сервера приложений Apache Tomcat, существующая из-за неполной очистки временных или вспомогательных ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240405-12

почти 2 года назад

Множественные уязвимости tomcat

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-42794

больше 2 лет назад

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Other, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2023-42794

больше 2 лет назад

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2023-42794

больше 2 лет назад

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Other, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-42794

больше 2 лет назад

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-jm7m-8jh6-29hp

больше 2 лет назад

Apache Tomcat Incomplete Cleanup vulnerability

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2024-0474

почти 2 года назад

ELSA-2024-0474: tomcat security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0125

около 2 лет назад

ELSA-2024-0125: tomcat security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0472-1

почти 2 года назад

Security update for tomcat

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-06729

Уязвимость компонента Commons FileUpload сервера приложений Apache Tomcat, существующая из-за неполной очистки временных или вспомогательных ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20240405-12

Множественные уязвимости tomcat

CVSS3: 7.5
почти 2 года назад
ubuntu логотип
CVE-2023-42794

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Other, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-42794

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-42794

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Other, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-42794

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork ...

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-jm7m-8jh6-29hp

Apache Tomcat Incomplete Cleanup vulnerability

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-0474

ELSA-2024-0474: tomcat security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-0125

ELSA-2024-0125: tomcat security update (MODERATE)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0472-1

Security update for tomcat

почти 2 года назад

Уязвимостей на страницу