elsa-2025-14179
oracle_linux
Description
[1:10.1.36-1.2] - tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988) - tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125) - apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976) - tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989) - tomcat: Apache Tomcat denial of service (CVE-2025-52520) - tomcat: Apache Tomcat denial of service (CVE-2025-53506)
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2025-52520",
"CVE-2025-49125",
"CVE-2025-48989",
"CVE-2025-48988",
"CVE-2025-53506",
"CVE-2025-48976"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[1:10.1.36-1.2]\n- tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988)\n- tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)\n- apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976)\n- tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)\n- tomcat: Apache Tomcat denial of service (CVE-2025-52520)\n- tomcat: Apache Tomcat denial of service (CVE-2025-53506)",
"id": "ELSA-2025-14179",
"ovalId": "oval:com.oracle.elsa:def:202514179",
"source": "oracle_linux",
"title": "ELSA-2025-14179: tomcat security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2025-14179.html"
}