CVE-2012-4557
Published Nov 30, 2012
Last updated a year ago
Overview
- Description
- The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-399
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:http_server:2.2.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "02B629FB-88C8-4E85-A137-28770F1E524E" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "03550EF0-DF89-42FE-BF0E-994514EBD947" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4886CCAB-6D4E-45C7-B177-2E8DBEA15531" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C35631AC-7C35-4F6A-A95A-3B080E5210ED" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CED2BA6-BE5E-4EF1-88EB-0DADD23D2EEF" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A71F4154-AD20-4EEA-9E2E-D3385C357DA5" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0B8C9DB-401E-42B3-BAED-D09A96DE9A90" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "062C20A0-05A0-4164-8330-DF6ADFE607F4" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D345BA35-93BB-406F-B5DC-86E49FB29C22" }, { "criteria": "cpe:2.3:a:apache:http_server:2.2.21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7ED4892F-C829-4BEA-AB82-6A78F6F2426D" } ], "operator": "OR" } ] } ]