VDB
RHSA-2012%3A1331
RHSA-2012%3A1331
PUBLISHED
CVSS 5 MEDIUM
Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Operations Network 3.1 |
Timeline
- Oct 3, 2012 CVE Published
- Jan 28, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2012:1331 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/knowledge/docs/ advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=em&version=3.1.1 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=783359 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_1331.json advisory
- https://access.redhat.com/security/cve/CVE-2012-0022 advisory
- https://www.cve.org/CVERecord?id=CVE-2012-0022 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-0022 advisory