elsa-2025-14179

oracle_linux
Description

[1:10.1.36-1.2] - tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988) - tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125) - apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976) - tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989) - tomcat: Apache Tomcat denial of service (CVE-2025-52520) - tomcat: Apache Tomcat denial of service (CVE-2025-53506)

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2025-52520",
    "CVE-2025-49125",
    "CVE-2025-48989",
    "CVE-2025-48988",
    "CVE-2025-53506",
    "CVE-2025-48976"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1:10.1.36-1.2]\n- tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988)\n- tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)\n- apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976)\n- tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)\n- tomcat: Apache Tomcat denial of service (CVE-2025-52520)\n- tomcat: Apache Tomcat denial of service (CVE-2025-53506)",
  "id": "ELSA-2025-14179",
  "ovalId": "oval:com.oracle.elsa:def:202514179",
  "source": "oracle_linux",
  "title": "ELSA-2025-14179:  tomcat security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-14179.html"
}
View JSON API Download JSON