{"id":"CVE-2012-0022","description":"Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.","cvssScore":5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","cvssMetrics":[{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-189"],"resolved":"NO-EXPLOIT-PUBLISHED","published":"2012-01-19","lastModified":"2026-06-16","affectedProducts":[{"vendor":"apache","product":"tomcat","version":"5.5.0"},{"vendor":"apache","product":"tomcat","version":"5.5.1"},{"vendor":"apache","product":"tomcat","version":"5.5.2"},{"vendor":"apache","product":"tomcat","version":"5.5.3"},{"vendor":"apache","product":"tomcat","version":"5.5.4"},{"vendor":"apache","product":"tomcat","version":"5.5.5"},{"vendor":"apache","product":"tomcat","version":"5.5.6"},{"vendor":"apache","product":"tomcat","version":"5.5.7"},{"vendor":"apache","product":"tomcat","version":"5.5.8"},{"vendor":"apache","product":"tomcat","version":"5.5.9"},{"vendor":"apache","product":"tomcat","version":"5.5.10"},{"vendor":"apache","product":"tomcat","version":"5.5.11"},{"vendor":"apache","product":"tomcat","version":"5.5.12"},{"vendor":"apache","product":"tomcat","version":"5.5.13"},{"vendor":"apache","product":"tomcat","version":"5.5.14"},{"vendor":"apache","product":"tomcat","version":"5.5.15"},{"vendor":"apache","product":"tomcat","version":"5.5.16"},{"vendor":"apache","product":"tomcat","version":"5.5.17"},{"vendor":"apache","product":"tomcat","version":"5.5.18"},{"vendor":"apache","product":"tomcat","version":"5.5.19"}],"totalAffectedProducts":1,"references":[{"url":"https://github.com/apache/tomcat55/commit/0314fe7743cb72e469cb395ccaaf2793a2ea0355","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat55/commit/7a1cfb6bd2f849806e7c060dda8648409ad8714e","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat55/commit/b05497eff4311a9657de6dfc53511d0309eb9db4","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/errata/RHSA-2012:0074","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/errata/RHSA-2012:0075","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/errata/RHSA-2012:0076","source":"osv","tags":["WEB"]},{"url":"https://access.redhat.com/errata/RHSA-2012:1331","source":"osv","tags":["WEB"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/72425","source":"osv","tags":["WEB"]},{"url":"https://github.com/apache/tomcat","source":"osv","tags":["PACKAGE"]},{"url":"https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e@%3Cdev.tomcat.apache.org%3E","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"no-exploit-published","decidingReason":"This CVE is not listed in CISA KEV, CISA Vulnrichment records no active exploitation, and no reviewed exploit catalogue carries an entry for it. Nobody has published something a stranger can run, so it is not a candidate for a rule ahead of the ones where somebody has; an upstream fix path does exist, so the remediation half of the candidacy still holds. This is a statement about what has been published, not about whether the defect is reachable or serious.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.tomcat:tomcat"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.tomcat:tomcat). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"no-match"},{"rule":"below-action-threshold","stage":"disposition","outcome":"withheld","detail":"CVE ships in Oracle Critical Patch Update January 2013 (CPU) — Oracle treats it as urgent, so severity does not settle it"},{"rule":"no-exploit-published","stage":"disposition","outcome":"matched","status":"NO-EXPLOIT-PUBLISHED","detail":"No working exploit has been published, and an upstream fix path does exist, so the remediation half of the candidacy still holds.","decisive":true}],"affectedProducts":[{"vendor":"apache","product":"tomcat","isKnown":true,"cpe":"cpe:2.3:a:apache:tomcat:5.5.0:*:*:*:*:*:*:*","source":"yaml"}],"affectedPackages":[{"name":"org.apache.tomcat:tomcat","introduced":"5.5.0","fixed":"5.5.35"},{"name":"org.apache.tomcat:tomcat","introduced":"6.0.0","fixed":"6.0.34"},{"name":"org.apache.tomcat:tomcat","introduced":"7.0.0","fixed":"7.0.23"}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update January 2013","releaseType":"CPU","quarter":"2013-Q1","url":"https://www.oracle.com/security-alerts/cpujan2013.html","products":[{"product":"Oracle Fusion Middleware","component":"Management Pack for Oracle GoldenGate","affectedVersions":"11.1.1.1.0"},{"product":"Oracle Fusion Middleware","component":"Oracle GoldenGate Veridata","affectedVersions":"3.0.0.11.0"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"unverified","type":"patch-rule"},"review":{"state":"automated","basis":"upstream-data"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.10478,"percentile":0.95494},"ssvc":{"available":false}}