Apache Tomcat AJP12 Protocol Remote DoS
Medium Nessus Network Monitor Plugin ID 2701
SynopsisThe remote host is vulnerable to a Denial of Service (DoS) attack.
DescriptionIt may be possible to freeze or crash the remote Tomcat web server by sending a specially crafted HTTP request. An attacker exploiting this flaw would only need to be able to send HTTP requests to the server. Successful exploitation would result in the web server being made unavailable to valid users.
SolutionUpgrade or patch according to vendor recommendations.