CVE-2011-4858
Summary
| CVE | CVE-2011-4858 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-01-05 19:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Tomcat | 5.5.35 | All | All | All |
| Application | Apache | Tomcat | 6.0.0 | All | All | All |
| Application | Apache | Tomcat | 6.0.1 | All | All | All |
| Application | Apache | Tomcat | 6.0.10 | All | All | All |
| Application | Apache | Tomcat | 6.0.11 | All | All | All |
| Application | Apache | Tomcat | 6.0.12 | All | All | All |
| Application | Apache | Tomcat | 6.0.13 | All | All | All |
| Application | Apache | Tomcat | 6.0.14 | All | All | All |
| Application | Apache | Tomcat | 6.0.15 | All | All | All |
| Application | Apache | Tomcat | 6.0.16 | All | All | All |
| Application | Apache | Tomcat | 6.0.17 | All | All | All |
| Application | Apache | Tomcat | 6.0.18 | All | All | All |
| Application | Apache | Tomcat | 6.0.19 | All | All | All |
| Application | Apache | Tomcat | 6.0.2 | All | All | All |
| Application | Apache | Tomcat | 6.0.20 | All | All | All |
| Application | Apache | Tomcat | 6.0.21 | All | All | All |
| Application | Apache | Tomcat | 6.0.22 | All | All | All |
| Application | Apache | Tomcat | 6.0.23 | All | All | All |
| Application | Apache | Tomcat | 6.0.24 | All | All | All |
| Application | Apache | Tomcat | 6.0.25 | All | All | All |
| Application | Apache | Tomcat | 6.0.26 | All | All | All |
| Application | Apache | Tomcat | 6.0.27 | All | All | All |
| Application | Apache | Tomcat | 6.0.28 | All | All | All |
| Application | Apache | Tomcat | 6.0.29 | All | All | All |
| Application | Apache | Tomcat | 6.0.3 | All | All | All |
| Application | Apache | Tomcat | 6.0.30 | All | All | All |
| Application | Apache | Tomcat | 6.0.31 | All | All | All |
| Application | Apache | Tomcat | 6.0.32 | All | All | All |
| Application | Apache | Tomcat | 6.0.33 | All | All | All |
| Application | Apache | Tomcat | 6.0.34 | All | All | All |
| Application | Apache | Tomcat | 6.0.4 | All | All | All |
| Application | Apache | Tomcat | 6.0.5 | All | All | All |
| Application | Apache | Tomcat | 6.0.6 | All | All | All |
| Application | Apache | Tomcat | 6.0.7 | All | All | All |
| Application | Apache | Tomcat | 6.0.8 | All | All | All |
| Application | Apache | Tomcat | 6.0.9 | All | All | All |
| Application | Apache | Tomcat | 7.0.0 | All | All | All |
| Application | Apache | Tomcat | 7.0.1 | All | All | All |
| Application | Apache | Tomcat | 7.0.10 | All | All | All |
| Application | Apache | Tomcat | 7.0.11 | All | All | All |
| Application | Apache | Tomcat | 7.0.12 | All | All | All |
| Application | Apache | Tomcat | 7.0.13 | All | All | All |
| Application | Apache | Tomcat | 7.0.14 | All | All | All |
| Application | Apache | Tomcat | 7.0.15 | All | All | All |
| Application | Apache | Tomcat | 7.0.16 | All | All | All |
| Application | Apache | Tomcat | 7.0.17 | All | All | All |
| Application | Apache | Tomcat | 7.0.18 | All | All | All |
| Application | Apache | Tomcat | 7.0.19 | All | All | All |
| Application | Apache | Tomcat | 7.0.2 | All | All | All |
| Application | Apache | Tomcat | 7.0.20 | All | All | All |
| Application | Apache | Tomcat | 7.0.21 | All | All | All |
| Application | Apache | Tomcat | 7.0.22 | All | All | All |
| Application | Apache | Tomcat | 7.0.3 | All | All | All |
| Application | Apache | Tomcat | 7.0.4 | All | All | All |
| Application | Apache | Tomcat | 7.0.5 | All | All | All |
| Application | Apache | Tomcat | 7.0.6 | All | All | All |
| Application | Apache | Tomcat | 7.0.7 | All | All | All |
| Application | Apache | Tomcat | 7.0.8 | All | All | All |
| Application | Apache | Tomcat | 7.0.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-2401-1 tomcat6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| '[security bulletin] HPSBMU02747 SSRT100771 rev.1 - HP OpenView Network Node Manager (OV NNM) Running' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Security Advisory SA48790 - Red Hat update for tomcat5 - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oCERT.org - oCERT Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.ocert.org | |
| HashCollision-DOS-POC/HashtablePOC.py at master · FireFart/HashCollision-DOS-POC · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| VU#903934 - Hash table implementations vulnerable to algorithmic complexity attacks | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| '[security bulletin] HPSBUX02860 SSRT101146 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remot' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Security Advisory SA54971 - IBM Tivoli Integrated Portal Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rhn.redhat.com/errata/RHSA-2012-0406.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Apache Tomcat 7 (7.0.23) - Changelog | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| rhn.redhat.com/errata/RHSA-2012-0089.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Security Advisory SA55115 - IBM Tivoli Dynamic Workload Console Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA48791 - Red Hat update for tomcat6 - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| 750521 – (CVE-2011-4084, CVE-2011-4858) CVE-2011-4858 tomcat: hash table collisions CPU usage DoS (oCERT-2011-003) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Apache Tomcat Hash Collision Denial Of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Best 7 Best Internet Security Software in 2019 | af854a3a-2127-422b-91ae-364da2661108 | www.nruns.com | |
| '[security bulletin] HPSBUX02741 SSRT100728 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remot' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| [SECURITY] Apache Tomcat and the hashtable collision DoS vulnerability | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | |
| [SECURITY] Apache Tomcat and the hashtable collision DoS vulnerability | MITRE | mail-archives.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.