VDB

RHSA-2014:0373

RHSA-2014:0373 PUBLISHED CVSS 5.800000190734863 MEDIUM

It was found that when Tomcat / JBoss Web processed a series of HTTP requests in which at least one request contained either multiple content-length headers, or one content-length header with a chunked transfer-encoding header, Tomcat / JBoss Web would incorrectly handle the request. A remote attacker could use this flaw to poison a web cache, perform cross-site scripting (XSS) attacks, or obtain sensitive information from other requests.

Risk Scores

CVSS 2.0
5.800000190734863

Affected Products

VendorProductVersions
Red HatRed Hat JBoss BPMS 6.0
Red HatRed Hat JBoss BRMS 6.0

Timeline

  • Apr 3, 2014 CVE Published
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • May 14, 2026 CVE Updated
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›