CyberRota Analysis
AI-GeneratedA buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake can be exploited by a malicious user to cause a denial-of-service (DoS) by crashing the Java Virtual Machine (JVM). This issue impacts versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8, with earlier unsupported versions potentially affected as well. Organizations using affected versions should prioritize upgrading to versions 1.3.9 or 2.0.16 to mitigate this high-severity risk.
Original NVD Description
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)