VDB
RHSA-2012%3A0345
RHSA-2012%3A0345
PUBLISHED
CVSS 5 MEDIUM
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Portal 4.3 |
Timeline
- Mar 1, 2012 CVE Published
- Jan 28, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2012:0345 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jbportal&downloadType=securityPatches&version=4.3+CP07 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=783359 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_0345.json advisory
- https://access.redhat.com/security/cve/CVE-2012-0022 advisory
- https://www.cve.org/CVERecord?id=CVE-2012-0022 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-0022 advisory