← All CVEs

CVE-2012-4557

medium · 5

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

5
CVSS
17.5%
EPSS (exploit prob.)
97th
EPSS percentile
2012-11-30
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
apachehttp_server2.2.12
apachehttp_server2.2.13
apachehttp_server2.2.14
apachehttp_server2.2.15
apachehttp_server2.2.16
apachehttp_server2.2.17
apachehttp_server2.2.18
apachehttp_server2.2.19
apachehttp_server2.2.20
apachehttp_server2.2.21

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-4557