Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0086

Опубликовано: 14 фев. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.

It was found that certain malformed requests caused RichFaces to leak memory. A remote, unauthenticated attacker could use this flaw to send a large number of malformed requests to a RichFaces application that uses the Atmosphere framework, leading to a denial of service (excessive memory consumption) on the application server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Portal 6richfacesAffected
Red Hat JBoss Portal 6.2FixedRHSA-2015:100914.05.2015
Red Hat JBoss Web Framework Kit 2.5FixedRHSA-2014:033526.03.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1067268RichFaces: remote denial of service via memory exhaustion

EPSS

Процентиль: 71%
0.01463
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.

github
около 4 лет назад

JBoss RichFaces Improper Input Validation vulnerability

EPSS

Процентиль: 71%
0.01463
Низкий

4.3 Medium

CVSS2