Vulnerability Name:
CVE-2012-5568 (CCN-80317)
Assigned:
2012-11-26
Published:
2012-11-26
Updated:
2021-01-11
Summary:
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
CVSS v3 Severity:
7.5 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
High
CVSS v2 Severity:
5.0 Medium
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
)
3.7 Low
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
7.8 High
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
)
5.8 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Complete
Vulnerability Type:
CWE-noinfo
Vulnerability Consequences:
Denial of Service
References:
Source: MISC
Type: Exploit, Third Party Advisory
http://captainholly.wordpress.com/2009/06/19/slowloris-vs-tomcat/
Source: MITRE
Type: CNA
CVE-2012-5568
Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2012:1700
Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2012:1701
Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2013:0147
Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20121125 Re: CVE Request: slowloris for tomcat
Source: CCN
Type: seclists Web site
Re: CVE Request: slowloris for tomcat
Source: CCN
Type: SA55714
Juniper Network and Security Manager Apache Tomcat Weakness and Vulnerability
Source: MLIST
Type: Vendor Advisory
[users] 20090619 How does Tomcat handle a slow HTTP DoS?
Source: MLIST
Type: Vendor Advisory
[users] 20090620 Re: How does Tomcat handle a slow HTTP DoS?
Source: CCN
Type: Apache Tomcat Web site
Apache Tomcat
Source: BID
Type: Third Party Advisory, VDB Entry
56686
Source: CCN
Type: BID-56686
Apache Tomcat CVE-2012-5568 Denial of Service Vulnerability
Source: CCN
Type: Red Hat Bugzilla Bug 880011
CVE-2012-5568 tomcat: Slowloris denial of service
Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=880011
Source: XF
Type: Third Party Advisory, VDB Entry
apache-tomcat-slowloris-dos(80317)
Source: XF
Type: UNKNOWN
apache-tomcat-slowloris-dos(80317)
Source: CCN
Type: JSA10600
Network and Security Manager: Apache Tomcat security update
Source: CCN
Type: IBM Security Bulletin 6858013 (Tivoli Application Dependency Discovery Manager)
TADDM affected by multiple vulnerabilities due to Apache Tomcat libraries
Vulnerable Configuration:
Configuration 1
:
cpe:/a:apache:tomcat:*:*:*:*:*:*:*:*
(Version >= 7.0.0 and <= 7.0.105)
Configuration 2
:
cpe:/o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
OR
cpe:/o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
OR
cpe:/o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:apache:tomcat:5.5.4:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.12:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.9:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.7:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.20:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.17:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.0:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.1:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.10:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.11:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.13:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.14:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.15:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.16:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.18:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.19:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.2:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.21:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.22:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.23:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.24:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.25:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.3:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.5:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.6:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.8:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.0:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.1:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.10:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.11:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.12:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.13:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.14:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.15:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.2:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.3:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.4:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.5:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.6:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.7:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.8:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.9:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.26:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.16:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.27:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.18:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.17:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.28:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.20:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.19:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.24:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.26:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.27:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.28:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.29:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.0:beta:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.1:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.2:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.3:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.4:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.8:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.5:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.6:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.7:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.9:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.10:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.11:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.29:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.30:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.31:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.32:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:5.5.33:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.30:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.31:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:6.0.32:*:*:*:*:*:*:*
OR
cpe:/a:apache:tomcat:7.0.0:*:*:*:*:*:*:*
AND
cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.3.0.0:*:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.opensuse.security:def:20125568
V
CVE-2012-5568
2022-05-20
oval:org.opensuse.security:def:26227
P
Security update for the Linux Kernel (Important)
2022-01-13
oval:org.opensuse.security:def:32290
P
Security update for apache2 (Important)
2022-01-12
oval:org.opensuse.security:def:32232
P
Security update for webkit2gtk3 (Important)
2021-12-01
oval:org.opensuse.security:def:32229
P
Security update for ruby2.1 (Important)
2021-12-01
oval:org.opensuse.security:def:26174
P
Security update for openexr (Moderate)
2021-12-01
oval:org.opensuse.security:def:33011
P
Security update for hivex (Moderate)
2021-09-23
oval:org.opensuse.security:def:32180
P
Security update for file (Important)
2021-09-02
oval:org.opensuse.security:def:32972
P
Security update for webkit2gtk3 (Important)
2021-08-03
oval:org.opensuse.security:def:32145
P
Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
2021-07-21
oval:org.opensuse.security:def:32124
P
Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
2021-06-18
oval:org.opensuse.security:def:42719
P
tomcat6-6.0.41-0.43.1 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:36312
P
tomcat6-6.0.41-0.43.1 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:26065
P
Security update for polkit (Important)
2021-06-03
oval:org.opensuse.security:def:32088
P
Security update for bind (Important)
2021-05-04
oval:org.opensuse.security:def:32268
P
Security update for openldap2 (Important)
2021-03-03
oval:org.opensuse.security:def:26203
P
Security update for openldap2 (Important)
2021-03-03
oval:org.opensuse.security:def:31732
P
Security update for krb5-appl (Important)
2021-02-19
oval:org.opensuse.security:def:26146
P
Security update for python3 (Important)
2021-02-08
oval:org.opensuse.security:def:42455
P
tomcat6-6.0.18-20.35.40.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:36048
P
tomcat6-6.0.18-20.35.40.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:31996
P
Security update for java-1_7_1-ibm (Moderate)
2020-12-01
oval:org.opensuse.security:def:32554
P
libltdl7 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25673
P
Security update for openldap2 (Important)
2020-12-01
oval:org.opensuse.security:def:26315
P
Security update for MozillaThunderbird (Moderate)
2020-12-01
oval:org.opensuse.security:def:25862
P
Recommended update for mariadb (Important)
2020-12-01
oval:org.opensuse.security:def:26491
P
Security update for nextcloud (Moderate)
2020-12-01
oval:org.opensuse.security:def:31968
P
Security update for ipmitool (Important)
2020-12-01
oval:org.opensuse.security:def:32598
P
python on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25801
P
Security update for libvdpau (Moderate)
2020-12-01
oval:org.opensuse.security:def:26329
P
Security update for znc (Low)
2020-12-01
oval:org.opensuse.security:def:25873
P
Security update for libcares2 (Low)
2020-12-01
oval:org.opensuse.security:def:26540
P
enscript on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:31514
P
Security update for quagga (Moderate)
2020-12-01
oval:org.opensuse.security:def:33236
P
ppc64-diag on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25882
P
Security update for python-tornado (Moderate)
2020-12-01
oval:org.opensuse.security:def:26373
P
Security update for ffmpeg (Moderate)
2020-12-01
oval:org.opensuse.security:def:25937
P
Security update for the Linux Kernel (Important)
2020-12-01
oval:org.opensuse.security:def:26579
P
libMagickCore1-32bit on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:31515
P
Security update for quagga (Low)
2020-12-01
oval:org.opensuse.security:def:33275
P
tomcat6 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25939
P
Security update for gstreamer-0_10-plugins-base (Moderate)
2020-12-01
oval:org.opensuse.security:def:27011
P
perl-32bit on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26593
P
libnetpbm10 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:31526
P
Security update for rsyslog (Moderate)
2020-12-01
oval:org.opensuse.security:def:31778
P
Security update for MozillaFirefox (Important)
2020-12-01
oval:org.opensuse.security:def:32388
P
Security update for tomcat6 (Important)
2020-12-01
oval:org.opensuse.security:def:26023
P
Security update for evince (Important)
2020-12-01
oval:org.opensuse.security:def:27046
P
tomcat6 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26637
P
ruby on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:31600
P
Security update for tightvnc (Important)
2020-12-01
oval:org.opensuse.security:def:31779
P
Security update for MozillaFirefox (Important)
2020-12-01
oval:org.opensuse.security:def:32444
P
Security update for xen (Important)
2020-12-01
oval:org.opensuse.security:def:25597
P
Security update for squid (Critical)
2020-12-01
oval:org.opensuse.security:def:27275
P
pure-ftpd on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:31790
P
Security update for MozillaFirefox (Moderate)
2020-12-01
oval:org.opensuse.security:def:32493
P
bzip2 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25598
P
Security update for curl (Moderate)
2020-12-01
oval:org.opensuse.security:def:26287
P
Security update for zeromq (Moderate)
2020-12-01
oval:org.opensuse.security:def:27310
P
tomcat6 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:31824
P
Security update for bash (Low)
2020-12-01
oval:org.opensuse.security:def:32334
P
Security update for samba (Important)
2020-12-01
oval:org.opensuse.security:def:31864
P
Security update for curl (Moderate)
2020-12-01
oval:org.opensuse.security:def:32532
P
java-1_4_2-ibm on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25609
P
Security update for sysstat (Moderate)
2020-12-01
oval:org.opensuse.security:def:26276
P
Security update for python (Moderate)
2020-12-01
oval:org.opensuse.security:def:25861
P
Security update for the Linux Kernel (Important)
2020-12-01
oval:org.opensuse.security:def:26438
P
Security update for ansible (Moderate)
2020-12-01
oval:org.opensuse.security:def:31881
P
Security update for dnsmasq (Important)
2020-12-01
oval:com.ubuntu.precise:def:20125568000
V
CVE-2012-5568 on Ubuntu 12.04 LTS (precise) - low.
2012-11-30
BACK
apache
tomcat *
opensuse
opensuse 11.4
opensuse
opensuse 12.1
opensuse
opensuse 12.2
apache
tomcat 5.5.4
apache
tomcat 5.5.12
apache
tomcat 5.5.9
apache
tomcat 5.5.7
apache
tomcat 5.5.20
apache
tomcat 5.5.17
apache
tomcat 5.5.0
apache
tomcat 5.5.1
apache
tomcat 5.5.10
apache
tomcat 5.5.11
apache
tomcat 5.5.13
apache
tomcat 5.5.14
apache
tomcat 5.5.15
apache
tomcat 5.5.16
apache
tomcat 5.5.18
apache
tomcat 5.5.19
apache
tomcat 5.5.2
apache
tomcat 5.5.21
apache
tomcat 5.5.22
apache
tomcat 5.5.23
apache
tomcat 5.5.24
apache
tomcat 5.5.25
apache
tomcat 5.5.3
apache
tomcat 5.5.5
apache
tomcat 5.5.6
apache
tomcat 5.5.8
apache
tomcat 6.0
apache
tomcat 6.0.0
apache
tomcat 6.0.1
apache
tomcat 6.0.10
apache
tomcat 6.0.11
apache
tomcat 6.0.12
apache
tomcat 6.0.13
apache
tomcat 6.0.14
apache
tomcat 6.0.15
apache
tomcat 6.0.2
apache
tomcat 6.0.3
apache
tomcat 6.0.4
apache
tomcat 6.0.5
apache
tomcat 6.0.6
apache
tomcat 6.0.7
apache
tomcat 6.0.8
apache
tomcat 6.0.9
apache
tomcat 5.5.26
apache
tomcat 6.0.16
apache
tomcat 5.5.27
apache
tomcat 6.0.18
apache
tomcat 6.0.17
apache
tomcat 5.5.28
apache
tomcat 6.0.20
apache
tomcat 6.0.19
apache
tomcat 6.0.24
apache
tomcat 6.0.26
apache
tomcat 6.0.27
apache
tomcat 6.0.28
apache
tomcat 6.0.29
apache
tomcat 7.0.0 beta
apache
tomcat 7.0.1
apache
tomcat 7.0.2
apache
tomcat 7.0.3
apache
tomcat 7.0.4
apache
tomcat 7.0.8
apache
tomcat 7.0.5
apache
tomcat 7.0.6
apache
tomcat 7.0.7
apache
tomcat 7.0.9
apache
tomcat 7.0.10
apache
tomcat 7.0.11
apache
tomcat 5.5.29
apache
tomcat 5.5.30
apache
tomcat 5.5.31
apache
tomcat 5.5.32
apache
tomcat 5.5.33
apache
tomcat 6.0.30
apache
tomcat 6.0.31
apache
tomcat 6.0.32
apache
tomcat 7.0.0
ibm
tivoli application dependency discovery manager 7.3.0.0