{"id":"CVE-2003-0045","aliases":[],"url":"https://o3.security/vulnerability/CVE-2003-0045","summary":"Jakarta Tomcat Denial of Service vulnerability","details":"Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.","published":"2022-04-29T01:25:43Z","modified":"2023-11-08T03:56:45.164061Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.tomcat:tomcat","fixedVersion":"3.3.1a"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0045"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12102"},{"type":"WEB","url":"http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:56:45.164061Z"}}