8: Denial of service via AJP requests with content length zero
Published May 31, 2014
5.0
MEDIUMCVSS 2.0
EPSS 8.49%
Description
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
tomcat5
Not affected
Red Hat Enterprise Linux 6
tomcat6
Not affected
Red Hat Enterprise Linux 7
tomcat
Not affected
Red Hat JBoss Enterprise Web Server 1
tomcat5
Not affected
Red Hat JBoss Enterprise Web Server 1
tomcat6
Not affected
Red Hat JBoss Enterprise Web Server 2
tomcat6
Not affected
Red Hat JBoss Enterprise Web Server 2
tomcat7
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | tomcat5 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | tomcat6 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | tomcat | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | tomcat5 | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | tomcat6 | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | tomcat6 | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | tomcat7 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect Apache Tomcat as shipped by any Red Hat product as it was introduced in Apache Tomcat 8.0.0-RC2 and did not affect earlier versions.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.49% (0.08494) | 94.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.49% (0.08494) | 94.31th | v5 (v2026.06.15) |
| Nov 2, 2025 | 9.66% (0.09656) | 92.58th | v4 (v2025.03.14) |
| Mar 30, 2025 | 13.06% (0.13063) | 93.48th | v4 (v2025.03.14) |
| Mar 29, 2025 | 18.53% (0.18532) | 92.18th | v4 (v2025.03.14) |
| Mar 17, 2025 | 13.06% (0.13063) | 93.55th | v4 (v2025.03.14) |
| Dec 17, 2024 | 10.66% (0.10655) | 95.04th | v3 (v2023.03.01) |
| Jan 11, 2024 | 3.03% (0.03029) | 89.94th | v3 (v2023.03.01) |
| Nov 25, 2023 | 4.07% (0.04074) | 91.17th | v3 (v2023.03.01) |
| Mar 7, 2023 | 4.05% (0.04048) | 90.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.72% (0.03718) | 85.08th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.72% (0.03718) | 83.56th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.72% (0.03718) | 66.71th | v2 (v2022.01.01) |
References (21)
- http://seclists.org/fulldisclosure/2014/May/134 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/59873 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60729 third-party-advisoryx_refsource_SECUNIA
- http://svn.apache.org/viewvc?view=revision&revision=1578392 x_refsource_CONFIRMPatch
- http://tomcat.apache.org/security-8.html x_refsource_CONFIRMVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21678231 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21681528 x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/67673 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1030300 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-0095 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1103804 Issue Tracking
- https://github.com/advisories/GHSA-wf5v-jhxj-q632 Advisory
- https://github.com/apache/tomcat/commit/8884dae60ace77a87ed9385442ce429e98c3a479
- https://github.com/apache/tomcat80/commit/77590c897f0e542fe363d70efdf3b82209510aee
- https://nvd.nist.gov/vuln/detail/CVE-2014-0095
- https://web.archive.org/web/20140713043210/http://www.securitytracker.com/id/1030300
- https://web.archive.org/web/20141126170141/http://www.securityfocus.com/bid/67673
- https://web.archive.org/web/20151017043748/http://secunia.com/advisories/60729
- https://web.archive.org/web/20161024215453/http://secunia.com/advisories/59873
- https://www.cve.org/CVERecord?id=CVE-2014-0095
Change history (0)
No recorded changes yet.