elsa-2025-14177

oracle_linux
Description

[1:9.0.87-1.el8_10.6] - Resolves: RHEL-102193 tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989) [1:9.0.87-1.el8_10.5] - Resolves: RHEL-108486 tomcat: Apache Commons FileUpload DOS via part headers (CVE-2025-48976) - Resolves: RHEL-108494 tomcat: Dos in multipart upload (CVE-2025-48988) - Resolves: RHEL-108502 tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125) - Resolves: RHEL-108510 tomcat: Denial of service (CVE-2025-52434) - Resolves: RHEL-108524 tomcat: Denial of service (CVE-2025-52520) - Resolves: RHEL-108518 tomcat: Denial of service (CVE-2025-53506)

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2025-48989",
    "CVE-2025-52520",
    "CVE-2025-48988",
    "CVE-2025-52434",
    "CVE-2025-49125",
    "CVE-2025-48976",
    "CVE-2025-53506"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1:9.0.87-1.el8_10.6]\n- Resolves: RHEL-102193\n  tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)\n\n[1:9.0.87-1.el8_10.5]\n- Resolves: RHEL-108486\n  tomcat: Apache Commons FileUpload DOS via part headers (CVE-2025-48976)\n- Resolves: RHEL-108494\n  tomcat: Dos in multipart upload (CVE-2025-48988)\n- Resolves: RHEL-108502\n  tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)\n- Resolves: RHEL-108510\n  tomcat: Denial of service (CVE-2025-52434)\n- Resolves: RHEL-108524\n  tomcat: Denial of service (CVE-2025-52520)\n- Resolves: RHEL-108518\n  tomcat: Denial of service (CVE-2025-53506)",
  "id": "ELSA-2025-14177",
  "ovalId": "oval:com.oracle.elsa:def:202514177",
  "source": "oracle_linux",
  "title": "ELSA-2025-14177:  tomcat security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-14177.html"
}
View JSON API Download JSON