Vulnerability
CVE-2002-2272
CVE-2002-2272 is a high-severity vulnerability (CVSS v2 7.8). As of 2026-10-09, 318 hosts in our data show software it affects on an open service in at least 15 countries.
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
- Published
- 2002-12-31
- Last modified
- 2026-06-16
- CVSS score
- 7.8 CVSS v2
- CVSS vector (v2)
- AV:N/AC:L/Au:N/C:N/I:N/A:C
- Exploit likelihood (EPSS)
- 9.7% in the next 30 days (higher than 95% of CVEs)
Exposure in our data
318 hosts
Hosts whose banner shows an affected software version on a service open at their latest check.
Not counted: 4 hosts with this CVE only from an older observation.
Not counted: 9 more on distribution builds that may be patched (the distribution may have backported the fix without changing the version).
2 more hosts had it earlier (the software version has since changed or the service is gone).
Counted 2026-10-09 08:20 UTC
By country
| United States US | 91 |
| Germany DE | 36 |
| Finland FI | 29 |
| Spain ES | 19 |
| Japan JP | 17 |
| Sweden SE | 11 |
| Switzerland CH | 9 |
| Italy IT | 9 |
| France FR | 7 |
| Hong Kong HK | 7 |
| Netherlands NL | 6 |
| Thailand TH | 6 |
| Australia AU | 5 |
| China CN | 5 |
| United Kingdom GB | 5 |
Affected software seen
| http_server 1.3.27 | 93 |
| http_server 1.3.26 | 65 |
| http_server 1.3.23 | 49 |
| http_server 1.3.20 | 25 |
| http_server 1.3.19 | 23 |
| http_server 1.3.11 | 21 |
| http_server 1.3.24 | 19 |
| http_server 1.3.12 | 11 |
| http_server 1.3.22 | 10 |
| http_server 1.3.17 | 2 |
| http_server 1.3.0 | 1 |