Apache Tomcat developers have released patches to fix three vulnerabilities in their implementations of the Java Servlet and JavaServer Pages technologies. When Tomcat receives a request with invalid headers via the Java AJP connector, it closes the connection without returning an error message. The vulnerability can be exploited by an attacker in load balancing environments to initiate a denial of service (DoS) attack. Read the full story [h-online.com: Tomcat patches are released to fix 3 vulnerabilities in Java Servlets and Java Server Pages.
Source: https://threatpost.com/vulnerabilities-fixed-apache-tomcat-060509/72726/

