Sploitus

CVE-2011-4858

6 known exploits for CVE-2011-4858

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Affected products
Apache Tomcat, Centos, Hp-Ux, Red Hat, Suse
Apache Tomcat
= 5.5.35, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.0.16, 6.0.17, 6.0.18, 6.0.19, 6.0.20, 6.0.21, 6.0.22, 6.0.23, 6.0.24, 6.0.25, 6.0.26, 6.0.27, 6.0.28, 6.0.29, 6.0.30, 6.0.31, 6.0.32, 6.0.33, 6.0.34, 7.0.0, 7.0.1, 7.0.2, 7.0.3
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
80.3% (100th percentile)
Weakness
CWE-399
NVD status
Modified
Published
2012-01-05
CVE-2011-4858 at NVD
Authoritative description, scoring and affected products

6 known exploits for CVE-2011-4858

Proof-of-concept code and exploit modules indexed by Sploitus