The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19284
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18938
https://bugzilla.redhat.com/show_bug.cgi?id=871685
http://www.debian.org/security/2012/dsa-2579
http://marc.info/?l=bugtraq&m=136612293908376&w=2
http://lists.opensuse.org/opensuse-updates/2013-02/msg00012.html
http://lists.opensuse.org/opensuse-updates/2013-02/msg00009.html
http://httpd.apache.org/security/vulnerabilities_22.html#2.2.22