Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5568

Опубликовано: 17 июн. 2009
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

Отчет

This issue affects tomcat and jbossweb as shipped in various Red Hat products. This issue can be mitigated using appropriate firewall configuration, as noted here: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-6750 This issue can also be partially mitigated by configuring an appropriate timeout using the connectionTimeout property for the relevant Connector(s) defined in server.xml, but testing shows that some variants of the attack may still be effective with this configuration. The tomcat project has advised that although this flaw can affect tomcat, there is no good solution available, and the tomcat security team does not consider it a vulnerability in tomcat or plan to release a patch: http://tomcat.apache.org/security-7.html#Not_a_vulnerability_in_Tomcat

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1unknownWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=880011tomcat: Slowloris denial of service

EPSS

Процентиль: 94%
0.12622
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

nvd
больше 12 лет назад

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

debian
больше 12 лет назад

Apache Tomcat through 7.0.x allows remote attackers to cause a denial ...

github
около 3 лет назад

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

EPSS

Процентиль: 94%
0.12622
Средний

5 Medium

CVSS2