httpd: mod_proxy_ajp remote temporary DoS
Published Mar 5, 2010
5.0
MEDIUMCVSS 2.0
EPSS 21.32%
Description
The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
Affected products
No data.
- 2.2
- 2.2.0
- 2.2.2
- 2.2.3
- 2.2.4
- 2.2.6
- 2.2.8
- 2.2.9
- 2.2.11
- 2.2.12
- 2.2.13
- 2.2.14
No data.
JBEWS 1.0 for RHEL 4
httpd22-0:2.2.14-11.jdk6.ep5.el4
Fixed · RHSA-2010:0396
Red Hat Enterprise Linux 5
httpd-0:2.2.3-31.el5_4.4
Fixed · RHSA-2010:0168
Red Hat JBoss Enterprise Web Server 1 for RHEL 5
httpd-0:2.2.14-1.2.6.jdk6.ep5.el5
Fixed · RHSA-2010:0396
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEWS 1.0 for RHEL 4 | httpd22-0:2.2.14-11.jdk6.ep5.el4 | Fixed | RHSA-2010:0396 |
| Red Hat Enterprise Linux 5 | httpd-0:2.2.3-31.el5_4.4 | Fixed | RHSA-2010:0168 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | httpd-0:2.2.14-1.2.6.jdk6.ep5.el5 | Fixed | RHSA-2010:0396 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (37 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 21.32% (0.21324) | 97.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 20.79% (0.20787) | 97.21th | v5 (v2026.06.15) |
| May 22, 2026 | 32.49% (0.32487) | 96.93th | v4 (v2025.03.14) |
| May 2, 2026 | 38.79% (0.38788) | 97.28th | v4 (v2025.03.14) |
| Mar 4, 2026 | 30.73% (0.30734) | 96.63th | v4 (v2025.03.14) |
| Mar 1, 2026 | 16.44% (0.16443) | 94.78th | v4 (v2025.03.14) |
| Feb 4, 2026 | 30.73% (0.30734) | 96.59th | v4 (v2025.03.14) |
| Feb 1, 2026 | 16.44% (0.16443) | 94.73th | v4 (v2025.03.14) |
| Jan 4, 2026 | 30.73% (0.30734) | 96.56th | v4 (v2025.03.14) |
| Jan 1, 2026 | 16.44% (0.16443) | 94.71th | v4 (v2025.03.14) |
| Dec 4, 2025 | 30.73% (0.30734) | 96.53th | v4 (v2025.03.14) |
| Dec 1, 2025 | 16.44% (0.16443) | 94.66th | v4 (v2025.03.14) |
| Nov 4, 2025 | 30.73% (0.30734) | 96.50th | v4 (v2025.03.14) |
| Nov 1, 2025 | 16.44% (0.16443) | 94.64th | v4 (v2025.03.14) |
| Oct 4, 2025 | 30.73% (0.30734) | 96.56th | v4 (v2025.03.14) |
| Oct 1, 2025 | 16.44% (0.16443) | 94.68th | v4 (v2025.03.14) |
| Sep 4, 2025 | 30.05% (0.30054) | 96.52th | v4 (v2025.03.14) |
| Sep 1, 2025 | 17.08% (0.17081) | 94.77th | v4 (v2025.03.14) |
| Aug 4, 2025 | 30.05% (0.30054) | 96.47th | v4 (v2025.03.14) |
| Aug 1, 2025 | 17.08% (0.17081) | 94.76th | v4 (v2025.03.14) |
| Jul 27, 2025 | 30.73% (0.30734) | 96.51th | v4 (v2025.03.14) |
| Jul 4, 2025 | 25.07% (0.25072) | 95.91th | v4 (v2025.03.14) |
| Jul 1, 2025 | 12.80% (0.12800) | 93.73th | v4 (v2025.03.14) |
| Jun 4, 2025 | 25.07% (0.25072) | 95.88th | v4 (v2025.03.14) |
| Jun 1, 2025 | 12.80% (0.12800) | 93.66th | v4 (v2025.03.14) |
| May 4, 2025 | 25.07% (0.25072) | 95.84th | v4 (v2025.03.14) |
| May 1, 2025 | 12.80% (0.12800) | 93.64th | v4 (v2025.03.14) |
| Mar 30, 2025 | 25.07% (0.25072) | 95.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 27.80% (0.27801) | 94.36th | v4 (v2025.03.14) |
| Mar 17, 2025 | 25.07% (0.25072) | 95.71th | v4 (v2025.03.14) |
| Dec 17, 2024 | 14.59% (0.14585) | 95.74th | v3 (v2023.03.01) |
| Dec 12, 2024 | 11.88% (0.11880) | 95.56th | v3 (v2023.03.01) |
| Nov 2, 2023 | 11.20% (0.11197) | 94.56th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.63% (0.03627) | 90.24th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07344) | 92.59th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.34% (0.07344) | 91.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.34% (0.07344) | 80.64th | v2 (v2022.01.01) |
No CWE recorded.
References (47)
- http://httpd.apache.org/security/vulnerabilities_22.html x_refsource_CONFIRMPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://marc.info/?l=bugtraq&m=127557640302499&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://secunia.com/advisories/39100 third-party-advisoryx_refsource_SECUNIAURL Repurposed
- http://secunia.com/advisories/39501 third-party-advisoryx_refsource_SECUNIAURL Repurposed
- http://secunia.com/advisories/39628 third-party-advisoryx_refsource_SECUNIAURL Repurposed
- http://secunia.com/advisories/39632 third-party-advisoryx_refsource_SECUNIAURL Repurposed
- http://secunia.com/advisories/39656 third-party-advisoryx_refsource_SECUNIAURL Repurposed
- http://secunia.com/advisories/40096 third-party-advisoryx_refsource_SECUNIAURL Repurposed
- http://support.apple.com/kb/HT4435 x_refsource_CONFIRMBroken Link
- http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/modules/proxy/mod_proxy_ajp.c?r1=917876&r2=917875&pathrev=917876 x_refsource_CONFIRMPatchThird Party Advisory
- http://svn.apache.org/viewvc?view=revision&revision=917876 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www.debian.org/security/2010/dsa-2035 vendor-advisoryx_refsource_DEBIANThird Party AdvisoryVDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:053 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 vendor-advisoryx_refsource_MANDRIVABroken LinkThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html x_refsource_CONFIRMThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0168.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/bid/38491 vdb-entryx_refsource_BIDBroken Link
- http://www.vupen.com/english/advisories/2010/0911 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/0994 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/1001 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/1057 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/1411 vdb-entryx_refsource_VUPENBroken Link
- https://access.redhat.com/security/cve/CVE-2010-0408 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=569905 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-0408
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8619 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9935 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2010-0408
Change history (0)
No recorded changes yet.