← Back

CVE-2002-1895

nvd nist
Published: Dec 31, 2002Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.

Affected (2)

Products: Apache: Tomcat
1 product
Tomcat
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Apache
Version 3.3
Version 4.0.4

References (12)

Timeline

No history available yet.