The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Mar 5, 2010 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2010-007 | Dec 16, 2011 | Mar 5, 2010 |
| Centos_linux | — | Upgrade httpdUpgrade httpd-develUpgrade mod_sslUpgrade httpd-manual | Dec 1, 2016 | Mar 5, 2010 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Mar 5, 2010 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Mar 5, 2010 |
| Oracle_linux | — | Upgrade mod_sslUpgrade httpdUpgrade httpd-manualUpgrade httpd-devel | Oct 16, 2024 | Mar 5, 2010 |
| Suse | — | Upgrade apache2-manualUpgrade apache2-example-pagesUpgrade apache2-preforkUpgrade apache2-develUpgrade apache2-eventUpgrade apache2-workerUpgrade apache2-utilsUpgrade apache2Upgrade apache2-doc | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade apache2.2-commonUpgrade apache2-common | Nov 8, 2024 | Mar 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub