Описание
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Certificate System 7.3 | Tomcat | Will not fix | ||
Red Hat Developer Suite v.3 | Platform | Will not fix | ||
Red Hat Satellite 5.4 | tomcat5 | Affected | ||
JBEWP 5 for RHEL 5 | jbossweb | Fixed | RHSA-2012:0076 | 31.01.2012 |
JBEWP 5 for RHEL 6 | jbossweb | Fixed | RHSA-2012:0076 | 31.01.2012 |
JBoss Communications Platform 5.1 | Fixed | RHSA-2012:0078 | 31.01.2012 | |
JBoss Enterprise BRMS Platform 5.1 | Fixed | RHSA-2012:0325 | 22.02.2012 | |
Red Hat Enterprise Linux 5 | tomcat5 | Fixed | RHSA-2012:0474 | 11.04.2012 |
Red Hat Enterprise Linux 6 | tomcat6 | Fixed | RHSA-2012:0475 | 11.04.2012 |
Red Hat JBoss Enterprise Application Platform 5.1 | Fixed | RHSA-2012:0075 | 31.01.2012 |
Показывать по
Дополнительная информация
Статус:
5 Medium
CVSS2
Связанные уязвимости
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7 ...
5 Medium
CVSS2