Impact
An allocation of resources without limits in Apache Tomcat’s AJP connector allows an unauthenticated client to send specially crafted requests that tie up an AJP processing thread. The effect is a denial of service where the victim's Tomcat instance can no longer process legitimate AJP traffic until a thread is freed, potentially causing service interruption for all AJP users.
Affected Systems
Apache Tomcat versions from 8.5.0 through 8.5.100, 7.0.0 through 7.0.109, 9.0.0.M1 through 9.0.121, 10.1.0-M1 through 10.1.59, and 11.0.0-M1 through 11.0.25 are affected. Versions prior to 8.5.0/7.0.0 and unlisted versions may also be vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting exploitation potential may be moderate. The vulnerability can be triggered by any external user capable of forming an AJP request, meaning the attack vector is network-based, remote, and unauthenticated. The impact is confined to service availability and does not compromise confidentiality or integrity directly.
OpenCVE Enrichment