Disclosure summary
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
Source-reported weakness categories
NVD-CWE-noinfo
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2012-5568
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| apache | tomcat | * {"versionStartIncluding":"7.0.0","versionEndIncluding":"7.0.105"} |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.1 |
| opensuse | opensuse | 12.2 |
Original records & references
- NIST NVD record
- CVE Program record
- bugzilla.redhat.com — Issue Tracking, Third Party Advisory
- exchange.xforce.ibmcloud.com — Third Party Advisory, VDB Entry
- bugzilla.redhat.com — Issue Tracking, Third Party Advisory
- exchange.xforce.ibmcloud.com — Third Party Advisory, VDB Entry
PUBLISHED 2012-11-30T14:55:01-05:00
MODIFIED 2026-10-09T16:17:04-04:00
INGESTED 2026-10-10T20:50:17-04:00