The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
2011-09-20T05:55:02.983
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | apache | http_server | ≤ 2.2.20 | Yes |
| Application | redhat | jboss_enterprise_web_server | 1.0.0 | Yes |
| Operating System | redhat | enterprise_linux | 6.0 | No |
| Operating System | redhat | enterprise_linux | 7.0 | No |