CVE-2002-2272
Apache Tomcat DoS via Malicious Get Request
EPSS 30.9%
Description
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
How to fix CVE-2002-2272
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Maven/org.apache.tomcat:tomcat—no fix listed
Is CVE-2002-2272 being exploited?
Moderate — EPSS is 30.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 4.0.0, <= 4.1.12