Miggo Logo

CVE-2003-0045: Jakarta Tomcat Denial of Service vulnerability

N/A

CVSS Score

Basic Information

EPSS Score
0.80362%
Published
4/29/2022
Updated
9/18/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.apache.tomcat:tomcatmaven< 3.3.1a3.3.1a

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability stems from improper handling of JSP requests containing reserved DOS device names. The JspServlet's service method is the primary entry point for JSP processing in Tomcat. While no patch details are available, historical context suggests this method would be responsible for filename resolution before file access operations. The lack of validation for reserved names in this function would directly lead to the described resource consumption scenario on Windows systems.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

J*k*rt* Tom**t ***or* *.*.** on **rt*in Win*ows syst*ms m*y *llow r*mot* *tt**k*rs to **us* * **ni*l o* s*rvi** (t*r*** **n* *n* r*sour** *onsumption) vi* * r*qu*st *or * JSP p*** *ont*inin* *n MS-*OS **vi** n*m*, su** *s *ux.jsp.

Reasoning

T** vuln*r**ility st*ms *rom improp*r **n*lin* o* JSP r*qu*sts *ont*inin* r*s*rv** *OS **vi** n*m*s. T** JspS*rvl*t's s*rvi** m*t*o* is t** prim*ry *ntry point *or JSP pro**ssin* in Tom**t. W*il* no p*t** **t*ils *r* *v*il**l*, *istori**l *ont*xt su*