Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Information Disclosure, DoS Flaws Patched in Apache Tomcat

The Apache Software Foundation informed users over the weekend that updates for the Tomcat application server address several vulnerabilities, including issues that can lead to information disclosure and a denial-of-service (DoS) condition.

The Apache Software Foundation informed users over the weekend that updates for the Tomcat application server address several vulnerabilities, including issues that can lead to information disclosure and a denial-of-service (DoS) condition.

Apache Tomcat is an open source implementation of the Java Servlet, JavaServer Pages (JSP), Java WebSocket and Java Expression Language technologies. Tomcat is the most widely used web application server, with a market share of over 60 percent.

One of the more serious flaws, CVE-2018-8037, impacts Tomcat versions 9.0.0.M9 through 9.0.9 and 8.5.5 through 8.5.31. Patches are included in Tomcat 9.0.10 and 8.5.32.Apache Tomcat vulnerabilities

The vulnerability, rated “important,” has been described by the Apache Software Foundation as an information disclosure issue caused by a bug in the tracking of connection closures that can lead to user sessions getting mixed up.

Another security hole rated “important” is CVE-2018-1336, a bug in the UTF-8 decoder that can lead to a DoS condition. The flaw affects Tomcat versions 7.0.x, 8.0.x, 8.5.x and 9.0.x, and it has been resolved with the release of versions 9.0.7, 8.5.32, 8.0.52 and 7.0.90.

“An improper handling of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service,” the Apache Software Foundation said in its advisory.

The latest Tomcat 7.0.x, 8.0.x, 8.5.x and 9.0.x releases also patch a low severity security constraints bypass issue tracked as CVE-2018-8034.

Advertisement. Scroll to continue reading.

“The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default,” reads the advisory for this vulnerability.

US-CERT has also released an alert, recommending that users review the Apache advisories and apply the updates.

Apache Tomcat vulnerabilities are less likely to be exploited in the wild. There was a worm targeting Apache Tomcat servers a few years ago, but it leveraged common username and password combinations rather than exploiting any vulnerabilities.

The Apache Software Foundation also informed customers last week of vulnerabilities impacting Apache Ignite, an open source memory-centric distributed database, caching, and processing platform. Ignite is currently ranked 66 by DB-Engines.

Ignite is impacted by two security holes, both of which could lead to arbitrary code execution .

Related: Code Execution Flaws Patched in Apache Tomcat

Related: Apache Struts Flaw Increasingly Exploited to Hack Servers

Related: One Year Later, Hackers Still Target Apache Struts Flaw

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.