CVE-2012-5568: Apache Tomcat

Medium severity, CVSS 5.0. EPSS: 9.6% chance of exploitation in the next 30 days.

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

Affected products

  • Apache Tomcat: from 7.0.0, up to and including 7.0.105
  • Opensuse Opensuse: version 11.4 only; version 12.1 only; version 12.2 only

Published 2012-11-30. Last modified 2026-10-09.