CVE-2002-2272 describes a denial-of-service vulnerability affecting Apache Tomcat versions 4.0 through 4.1.12 when used with mod_jk 1.2.1 on Apache HTTP Server 1.3 through 1.3.27. An unauthenticated remote attacker can exploit this by sending a malformed HTTP GET request containing an invalid Transfer-Encoding chunked field, leading to desynchronized communications. This vulnerability has a high CVSS score of 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C), indicating it can be exploited remotely with low complexity and results in a complete denial of service. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered significant community discussion, though no Metasploit or Nuclei modules are available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:* | ||
1.3.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.0:*:*:*:*:*:*:* | ||
1.3.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:* | ||
1.3.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.2:*:*:*:*:*:*:* | ||
1.3.10CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.