CVE Vulnerabilities

CVE-2012-4557

Published: Nov 30, 2012 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.

Affected Software

Name Vendor Start Version End Version
Http_server Apache 2.2.12 (including) 2.2.12 (including)
Http_server Apache 2.2.13 (including) 2.2.13 (including)
Http_server Apache 2.2.14 (including) 2.2.14 (including)
Http_server Apache 2.2.15 (including) 2.2.15 (including)
Http_server Apache 2.2.16 (including) 2.2.16 (including)
Http_server Apache 2.2.17 (including) 2.2.17 (including)
Http_server Apache 2.2.18 (including) 2.2.18 (including)
Http_server Apache 2.2.19 (including) 2.2.19 (including)
Http_server Apache 2.2.20 (including) 2.2.20 (including)
Http_server Apache 2.2.21 (including) 2.2.21 (including)
JBEWS 1.0 for RHEL 4 RedHat ant-0:1.7.1-13.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat antlr-0:2.7.7-7.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat bcel-0:5.2-8.1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat cglib-0:2.2-5.1.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat dom4j-0:1.6.1-11.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat ecj-1:3.3.1.1-3.2.2.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat glassfish-jaf-0:1.1.0-6.1.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat glassfish-javamail-0:1.4.2-0.4.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat glassfish-jsf-0:1.2_13-2.2.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat hibernate3-1:3.3.2-1.5.GA_CP04.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat hibernate3-annotations-0:3.4.0-3.3.GA_CP04.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat hibernate3-commons-annotations-0:3.1.0-1.8.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat hibernate3-ejb-persistence-3.0-api-1:1.0.2-3.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat hibernate3-entitymanager-0:3.4.0-4.3.GA_CP04.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat httpd22-0:2.2.17-14.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-beanutils-0:1.8.0-4.1.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-chain-0:1.2-2.2.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-codec-0:1.3-9.1.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-collections-0:3.2.1-4.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-daemon-1:1.0.5-1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-daemon-jsvc-1:1.0.5-1.4.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-dbcp-0:1.2.1-16.4.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-digester-0:1.8.1-8.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-el-0:1.0-19.2.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-fileupload-1:1.1.1-7.4.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-httpclient-1:3.1-1.1.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-io-0:1.4-1.3.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-launcher-0:1.1-4.6.1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-logging-0:1.1.1-0.4.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-logging-jboss-0:1.1-10.2.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-modeler-0:2.0-4.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-pool-0:1.3-11.2.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-commons-validator-0:1.3.1-7.5.1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-oro-0:2.0.8-3.3.2.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jakarta-taglibs-standard-0:1.1.1-9.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat javassist-0:3.12.0-1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jboss-common-core-0:2.2.17-1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jboss-common-logging-jdk-0:2.1.2-1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jboss-common-logging-spi-0:2.1.2-1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jboss-javaee-0:5.0.1-2.9.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jcommon-0:1.0.16-1.2.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat jfreechart-0:1.0.13-2.3.2.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat log4j-0:1.2.14-18.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat mod_cluster-0:1.0.10-2.GA_CP01.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat mod_cluster-native-0:1.0.10-2.GA_CP01.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat mod_jk-0:1.2.31-1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat mx4j-1:3.0.1-9.3.4.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat objectweb-asm-0:3.1-5.3.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat regexp-0:1.5-1.2.1.jdk6.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat struts12-0:1.2.9-3.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat tomcat5-0:5.5.33-14_patch_04.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat tomcat6-0:6.0.32-15_patch_03.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat tomcat-jkstatus-ant-0:1.2.31-2.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat tomcat-native-0:1.1.20-2.0.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat xalan-j2-0:2.7.1-5.3_patch_04.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat xerces-j2-0:2.9.1-3.patch01.1.ep5.el4 *
JBEWS 1.0 for RHEL 4 RedHat xml-commons-1:1.3.04-7.12.ep5.el4 *
Red Hat Enterprise Linux 6 RedHat httpd-0:2.2.15-26.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat ant-0:1.7.1-13.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat antlr-0:2.7.7-7.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat cglib-0:2.2-5.1.1.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat dom4j-0:1.6.1-11.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat ecj3-1:3.3.1.1-3.1.1.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat glassfish-jsf-0:1.2_13-3.1.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat hibernate3-1:3.3.2-1.4.GA_CP04.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat hibernate3-annotations-0:3.4.0-3.2.GA_CP04.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat hibernate3-commons-annotations-0:3.1.0-1.8.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat hibernate3-ejb-persistence-3.0-api-1:1.0.2-3.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat hibernate3-entitymanager-0:3.4.0-4.3.GA_CP04.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat httpd-0:2.2.17-11.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-beanutils-0:1.8.0-4.1.2.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-chain-0:1.2-2.2.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-codec-0:1.3-9.2.1.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-collections-0:3.2.1-4.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-daemon-1:1.0.5-1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-daemon-jsvc-1:1.0.5-1.4.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-dbcp-0:1.2.1-16.4.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-digester-0:1.8.1-8.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-fileupload-1:1.1.1-7.4.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-httpclient-1:3.1-1.2.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-io-0:1.4-1.3.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-logging-0:1.1.1-0.4.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-logging-jboss-0:1.1-10.2.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-pool-0:1.3-11.2.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-commons-validator-0:1.3.1-7.5.2.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-oro-0:2.0.8-3.3.2.1.1.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jakarta-taglibs-standard-0:1.1.1-9.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat javassist-0:3.12.0-1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jboss-common-core-0:2.2.17-1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jboss-common-logging-jdk-0:2.1.2-1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jboss-common-logging-spi-0:2.1.2-1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jboss-javaee-0:5.0.1-2.9.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jcommon-0:1.0.16-1.2.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat jfreechart-0:1.0.13-2.3.2.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat mod_cluster-0:1.0.10-2.1.GA_CP01.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat mod_cluster-native-0:1.0.10-2.1.GA_CP01.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat mod_jk-0:1.2.31-1.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat objectweb-asm-0:3.1-5.3.1.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat struts12-0:1.2.9-3.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat tomcat5-0:5.5.33-16_patch_04.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat tomcat6-0:6.0.32-15.1_patch_03.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat tomcat-jkstatus-ant-0:1.2.31-2.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat tomcat-native-0:1.1.20-2.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat xalan-j2-0:2.7.1-5.3_patch_04.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat xerces-j2-0:2.9.1-3.patch01.1.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 RedHat xml-commons-0:1.3.04-7.10.jdk6.ep5.el5 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat ant-0:1.7.1-14.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat antlr-0:2.7.7-7.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat cglib-0:2.2-5.4.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat dom4j-0:1.6.1-11.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat ecj3-1:3.3.1.1-4.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat glassfish-jsf-0:1.2_13-3.1.4.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat hibernate3-1:3.3.2-1.8.GA_CP04.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat hibernate3-annotations-0:3.4.0-3.5.GA_CP04.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat hibernate3-commons-annotations-0:3.1.0-1.8.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat hibernate3-ejb-persistence-3.0-api-1:1.0.2-3.3.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat hibernate3-entitymanager-0:3.4.0-4.4.GA_CP04.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat httpd-0:2.2.17-11.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-beanutils-0:1.8.0-9.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-chain-0:1.2-2.2.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-codec-0:1.3-12.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-collections-0:3.2.1-4.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-daemon-1:1.0.5-1.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-daemon-jsvc-1:1.0.5-1.4.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-dbcp-0:1.2.1-16.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-digester-0:1.8.1-8.1.1.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-fileupload-1:1.1.1-7.5.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-httpclient-1:3.1-1.2.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-io-0:1.4-4.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-logging-0:1.1.1-1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-logging-jboss-0:1.1-10.2.2.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-pool-0:1.3-15.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-commons-validator-0:1.3.1-7.5.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-oro-0:2.0.8-7.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jakarta-taglibs-standard-0:1.1.1-12.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat javassist-0:3.12.0-3.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jboss-common-core-0:2.2.17-1.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jboss-common-logging-jdk-0:2.1.2-1.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jboss-common-logging-spi-0:2.1.2-1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jboss-javaee-0:5.0.1-2.9.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jcommon-0:1.0.16-1.2.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat jfreechart-0:1.0.13-2.3.2.1.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat mod_cluster-0:1.0.10-2.2.GA_CP01.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat mod_cluster-native-0:1.0.10-2.1.1.GA_CP01.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat mod_jk-0:1.2.31-1.1.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat objectweb-asm31-0:3.1-12.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat struts12-0:1.2.9-3.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat tomcat5-0:5.5.33-15_patch_04.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat tomcat6-0:6.0.32-14_patch_03.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat tomcat-jkstatus-ant-0:1.2.31-2.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat tomcat-native-0:1.1.20-2.1.2.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat xalan-j2-0:2.7.1-5.3_patch_04.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat xerces-j2-0:2.9.1-8.patch01.1.ep5.el6 *
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 RedHat xml-commons-0:1.3.04-7.14.ep5.el6 *
Red Hat JBoss Web Server 1.0 RedHat *
Apache2 Ubuntu hardy *
Apache2 Ubuntu lucid *
Apache2 Ubuntu oneiric *
Apache2 Ubuntu upstream *

References