HTTP: POST Submission Missing Data
This signature detects a POST submission that does not include the POST data in the first packet payload. This may be an indication of a Denial of Service (DoS) using the 'Slowloris' technique. It also may be a non-malicious submission with a low MTU.
Extended Description
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
Affected Products
Apache tomcat
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Apache
6.8
5.0