[Japanese]
|
JVNDB-2025-000044
|
Denial-of-service (DoS) vulnerabilities in multiple Apache products
|
Multiple Apache products provided by The Apache Software Foundation contain vulnerabilities listed below.
- Allocation of resources without limits or throttling (CWE-770) - CVE-2025-48976, CVE-2025-48988
TERASOLUNA Framework Security Team of NTT DATA Group Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 5.3 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
|
The versions of Apache Tomcat are also affected by CVE-2025-48976 as Tomcat includes a fork of Commons FileUpload.
|
Apache Software Foundation
- Apache Tomcat 11.0.0-M1 to 11.0.7 (CVE-2025-48988)
- Apache Tomcat 10.1.0-M1 to 10.1.41 (CVE-2025-48988)
- Apache Tomcat 9.0.0.M1 to 9.0.105 (CVE-2025-48988)
- Commons FileUpload 1.0 before 1.6 (CVE-2025-48976)
- Commons FileUpload 2.0.0-M1 before 2.0.0-M4 (CVE-2025-48976)
|
|
- Allocation of resources for multipart headers with insufficient limits may lead to a denial-of-service (DoS) condition (CVE-2025-48976)
- Allocation of resources without limits or throttling may lead to a denial-of-service (DoS) condition (CVE-2025-48988)
|
[Update the Software]
Update the software to the latest version according to the information provided by the developer.
CVE-2025-48976
- Apache Commons FileUpload 1.6 or later
- Apache Commons FileUpload 2.0.0-M4 or later
CVE-2025-48988
- Apache Tomcat 11.0.8 or later
- Apache Tomcat 10.1.42 or later
- Apache Tomcat 9.0.106 or later
For more information, refer to the information provided by the developer.
|
Apache Software Foundation
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2025-48976
- CVE-2025-48988
|
- JVN : JVN#09924566
|
- [2025/06/26]
Web page was published
|