Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0109

Опубликовано: 01 мая 2014
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.

A denial of service flaw was found in the way Apache CXF created error messages for certain POST requests. A remote attacker could send a specially crafted request which, when processed by an application using Apache CXF, could consume an excessive amount of memory on the system, possibly triggering an Out Of Memory (OOM) error.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1cxfWill not fix
Red Hat BPM Suite 6cxfAffected
Red Hat JBoss BRMS 5cxfWill not fix
Red Hat JBoss BRMS 6cxfAffected
Red Hat JBoss Enterprise Web Server 1amq-6.1Affected
Red Hat JBoss Enterprise Web Server 1amq-7.1Will not fix
Red Hat JBoss Enterprise Web Server 1fuse-6.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-7.1Will not fix
Red Hat JBoss Fuse Service Works 6cxfAffected
Red Hat JBoss Portal 6cxfAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1093526CXF: HTML content posted to SOAP endpoint could cause OOM errors

EPSS

Процентиль: 91%
0.06069
Низкий

3.5 Low

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.

github
больше 3 лет назад

Uncontrolled Resource Consumption in Apache CXF

EPSS

Процентиль: 91%
0.06069
Низкий

3.5 Low

CVSS2