5
CVSSv2

CVE-2012-5568

Published: 30/11/2012 Updated: 11/01/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache Tomcat up to and including 7.0.x allows remote malicious users to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat

opensuse opensuse 11.4

opensuse opensuse 12.1

opensuse opensuse 12.2

Github Repositories

pwnloris An improved slowloris DOS tool which keeps attacking until the server starts getting exhausted Detailed info This tool abuses the CVE-2007-6750 and CVE-2012-5568 vulnerabilities The exploits works by using just one machine by creating multiple threads and sending from each thread incomplete requests while keeping the connections alive thus using up all the resources

This script successfully exploits: CVE-2007-6750, CVE-2012-5568