VDB
RHSA-2014%3A1149
RHSA-2014%3A1149
PUBLISHED
CVSS 4.300000190734863 MEDIUM
It was discovered that JBoss Web / Apache Tomcat did not limit the length of chunk sizes when using chunked transfer encoding. A remote attacker could use this flaw to perform a denial of service attack against JBoss Web / Apache Tomcat by streaming an unlimited quantity of data, leading to excessive consumption of server resources.
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Operations Network 3.2 |
Timeline
- Sep 3, 2014 CVE Published
- Jan 28, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2014:1149 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=em&downloadType=securityPatches&version=3.2.0 advisory
- https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1072776 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1102030 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1149.json advisory
- https://access.redhat.com/security/cve/CVE-2014-0075 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0075 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0075 advisory
- https://access.redhat.com/security/cve/CVE-2014-0099 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0099 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0099 advisory