• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – Emotet, A Banking Trojan Responsible For Network-Wide Infection
July 20, 2018
Rewterz Threat Intelligence Report 2018
August 3, 2018

Rewterz Threat Advisory – CVE-2018-1336 and CVE-2018-8037 Apache Releases Security Updates for Apache Tomcat

July 23, 2018

This is an advisory on security updates released by The Apache Software Foundation to address vulnerabilities in Apache Tomcat.

 

IMPACT:  CRITICAL

PUBLISH DATE:  23-07-2018

 

OVERVIEW

The Apache Software Foundation has recently released updates to patch the vulnerabilities found in some versions of the Apache Tomcat. These vulnerabilities can be exploited to obtain sensitive information.

 

BACKGROUND INFORMATION

The Apache Software Foundation has discovered two vulnerabilities in the Apache Tomcat software. CVE-2018-1336 Apache Tomcat – Denial of Service vulnerability, and CVE-2018-8037 Apache Tomcat – Information Disclosure vulnerability, were found on July 22nd, that have been patched by the Apache Software Foundation the following day.

 

The addressed vulnerabilities were found in the Apache Tomcat versions 9.0.0.M9 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

 

WORK FLOW ANALYSIS

CVE-2018-1336 is an Apache Tomcat Denial of Service vulnerability. Tomcat uses the UTF-8 decoder of the late Apache Harmony project, that decoder has a not supported edge case (aka Bug), which can lead to an infinite loop while trying to decode UTF-8 encoded characters, when an overflow in the UTF-8 décor is mishandled. Thus, the infinite loop leads to Denial of Service (DoS).

 

CVE-2018-8037 is an Apache Tomcat Information Disclosure vulnerability. It occurs due to a bug in the tracking of connection closures, that can lead to reuse of user sessions in a new connection. It seems that the researchers are not yet entirely clear on what factor triggered this potentially grave vulnerability of mixed up user sessions in the NIO and NIO2 connectors. According to the reporter it was accompanied by several exceptions happening in the same time frame.

 

AVAILABLE UPDATES

 

Updates for CVE-2018-8037:

 

Affected version Upgrade to
Apache Tomcat 9.0.0.M9 to 9.0.9 Apache Tomcat 9.0.10 or later.
Apache Tomcat 8.5.5 to 8.5.31 Apache Tomcat 8.5.32 or later.

 

 

Updates for CVE-2018-1336:

 

Affected version Upgrade to
Apache Tomcat 9.0.0.M9 to 9.0.7 Apache Tomcat 9.0.7 or later
Apache Tomcat 8.5.0 to 8.5.30 Apache Tomcat 8.5.32 or later
Apache Tomcat 8.0.0.RC1 to 8.0.51 Apache Tomcat 8.0.52 or later
Apache Tomcat 7.0.28 to 7.0.86 Apache Tomcat 7.0.90 or later

 

RESOLVE 

To stay safe from known vulnerabilities, we advise you to update your Tomcat installations each time a new Tomcat patch release is announced.

                       

 

If you think you are a victim of a cyber-security attack. Immediately send an email to info@rewterz.com for a rapid response.

  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.