peter bassill · operator
$ cve CVE-2011-4858 JSON

CVE-2011-4858 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 79.7% (pctl 100)

Patch early

A public exploit exists.

Description

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS79.71% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2012-01-05
Last modified2026-06-16

Affected (1)

VendorProduct
apachetomcat

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD