← Vulnerability feed

Vulnerability record · CVE-2011-3348 · published 20 September 2011

CVE-2011-3348: Apache http server uncontrolled resource consumption vulnerability

Apache · Http Server

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

4.3 CVSS 2.0 Medium EPSS 22% · top 2.4% CWE-400 · Uncontrolled resource consumption
4.3CVSS 2.0 base score
22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
60References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://community.jboss.org/message/625307 ExploitThird Party Advisory
http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21 Vendor Advisory
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html Broken LinkMailing List
http://marc.info/?l=bugtraq&m=131731002122529&w=2 Issue TrackingMailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=132033751509019&w=2 Issue TrackingMailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0542.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0543.html Third Party Advisory
http://secunia.com/advisories/46013 Not ApplicableVendor Advisory
http://support.apple.com/kb/HT5130 Third Party Advisory
http://www.apache.org/dist/httpd/Announcement2.2.html Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2011:168 Broken Link
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-1391.html Third Party Advisory
http://www.securityfocus.com/bid/49616 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1026054 Broken LinkThird Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/69804 Third Party AdvisoryVDB Entry
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14941 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18154 Third Party Advisory
http://community.jboss.org/message/625307 ExploitThird Party Advisory
http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21 Vendor Advisory
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html Broken LinkMailing List
http://marc.info/?l=bugtraq&m=131731002122529&w=2 Issue TrackingMailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=132033751509019&w=2 Issue TrackingMailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0542.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-0543.html Third Party Advisory
http://secunia.com/advisories/46013 Not ApplicableVendor Advisory
http://support.apple.com/kb/HT5130 Third Party Advisory
http://www.apache.org/dist/httpd/Announcement2.2.html Broken Link

Track CVE-2011-3348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed8.1CVE-2017-12615Apache Tomcat on Windows unrestricted JSP upload via HTTP PUTApache Tomcat 7.0.0 through 7.0.79 on Windows with HTTP PUT enabled (for example, Default servlet readonly set to false) allows an attacker to upload…KEVEPSS 100%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2011-3348), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.