CVE-2012-0022
Denial of Service in Apache Tomcat
EPSS 23.2%
Description
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
How to fix CVE-2012-0022
To remediate CVE-2012-0022, upgrade the affected package to a fixed version below.
- Maven/org.apache.tomcat:tomcat—upgrade to 5.5.35 or later
Is CVE-2012-0022 being exploited?
Moderate — EPSS is 23.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 5.5.0, < 5.5.35