<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by NGFW in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/433258#M1314</link>
    <description>&lt;P&gt;&lt;U&gt;&lt;FONT color="#333333"&gt;An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the request object was not reset between requests.&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333333"&gt;&lt;A href="https://apps.apple.com/us/app/dinar-guru-top-dinar-recaps/id1581089419" target="_self"&gt;&lt;FONT color="#333333"&gt;Dinar Guru&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Sep 2021 09:06:34 GMT</pubDate>
    <dc:creator>Gregg65</dc:creator>
    <dc:date>2021-09-11T09:06:34Z</dc:date>
    <item>
      <title>Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/353103#M959</link>
      <description>&lt;P&gt;RE:&amp;nbsp;&lt;SPAN&gt;'Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by PAN NGFW detected on host foo-wrkXXX involving user foo\User.Name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-- Unique Threat ID: 59026&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am wondering if others are seeing this Alert generated due to what appears to be mostly client updates of OneNote (and perhaps other cloud apps). Looking at the threat ID, I see it was released on 13 Aug and as of today, there has not been an update to it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a client that since 17 Aug, has generated 54 Incidents in Cortex. &amp;nbsp;As we do not manage or have access client Panorama to change Profile and perhaps disable this alert for outbound client connectivity, wondering if perhaps others have seen it and have a PCAP sent to PANW so that they can update the signature to be more effective?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 19:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/353103#M959</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2020-09-30T19:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/401554#M1131</link>
      <description>&lt;P&gt;We are also seeing this error tied to M365. Client reports that they have issues logging in and updating OneNote.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 17:32:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/401554#M1131</guid>
      <dc:creator>GFrostad</dc:creator>
      <dc:date>2021-04-23T17:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/423334#M1259</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136463"&gt;@KRisselada&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/123343"&gt;@GFrostad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever find a resolution to this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a client that seems to be experiencing the same issue, when redistributing note's in One Note on MAC iOS Mojave. Client advised they updated a machine to iOS Vigsur and the issue was fixed on that machine. Windows 10 machine seem to be unaffected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 05:35:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/423334#M1259</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-07-30T05:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/430410#M1293</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181759"&gt;@Ben-Price&lt;/a&gt;&amp;nbsp;sorry just realizing this was asked.&amp;nbsp; Actually we applied a Incident Exception, so we stopped having it generated for what appears to be "normal" behaivor.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 13:28:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/430410#M1293</guid>
      <dc:creator>KRisselada</dc:creator>
      <dc:date>2021-08-31T13:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/430622#M1294</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/166820"&gt;@KRisselada&lt;/a&gt;&amp;nbsp;Thanks for the feedback.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 23:06:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/430622#M1294</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-08-31T23:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat WebSocket Denial-of-Service Vulnerability' generated by NGFW</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/433258#M1314</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;FONT color="#333333"&gt;An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the request object was not reset between requests.&lt;/FONT&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#333333"&gt;&lt;A href="https://apps.apple.com/us/app/dinar-guru-top-dinar-recaps/id1581089419" target="_self"&gt;&lt;FONT color="#333333"&gt;Dinar Guru&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 09:06:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/apache-tomcat-websocket-denial-of-service-vulnerability/m-p/433258#M1314</guid>
      <dc:creator>Gregg65</dc:creator>
      <dc:date>2021-09-11T09:06:34Z</dc:date>
    </item>
  </channel>
</rss>

