DX NetOps Mediation Manager: CVE-2023-24998 - Apache Tomcat denial of service
search cancel

DX NetOps Mediation Manager: CVE-2023-24998 - Apache Tomcat denial of service

book

Article ID: 261162

calendar_today

Updated On:

Products

DX NetOps CA Mediation Manager

Issue/Introduction

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed, resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

Environment

All Mediation Manager Releases

Resolution

You must upgrade to 22.2.7 once it is released to resolve this vulnerability.

DX NetOps 22.2.7 will release Tomcat 9.0.71.

DX NetOps 22.2.7 is due out in late March but is subject to change.

There is, unfortunately, no workaround for this issue.