If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
We have discovered 978,452 live websites that are affected by CVE-2022-22721.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 978,452 live websites (37% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 44 versions ( 37% of all versions) |
| 295,614 websites | |
| 106,373 websites | |
| 55,617 websites | |
| 41,755 websites | |
| 40,800 websites | |
| 34,289 websites | |
| 33,411 websites | |
| 30,018 websites | |
| 26,895 websites | |
| 25,344 websites |
| .com | 364,928 websites |
| .de | 62,599 websites |
| .org | 46,002 websites |
| .net | 38,665 websites |
| .ru | 36,688 websites |
| .it | 30,412 websites |
| .nl | 22,364 websites |
| .cz | 20,841 websites |
| .pl | 20,371 websites |
| .jp | 18,112 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| *************.***.****.****.************.net | *** | ||
| *********.net | *** | ||
| ***.****.us | *,*** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** | ||
| ******************.com | *,*** | ||
| ****.*********.net | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** |
FAQ