CVE-2012-4557: Apache HTTP Server
Medium severity, CVSS 5.0. EPSS: 17.5% chance of exploitation in the next 30 days.
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
Affected products
- Apache HTTP Server: version 2.2.12 only; version 2.2.13 only; version 2.2.14 only; version 2.2.15 only; version 2.2.16 only; version 2.2.17 only; …
Published 2012-11-30. Last modified 2026-06-16.