Описание
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | karaf | Not affected | ||
| Red Hat JBoss BRMS 6 | karaf | Not affected | ||
| Red Hat JBoss Fuse Service Works 6 | karaf | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Low
https://bugzilla.redhat.com/show_bug.cgi?id=1095974Karaf: denial of service via shutdown port
EPSS
Процентиль: 50%
0.00697
Низкий
2.1 Low
CVSS2
Связанные уязвимости
CVSS3: 5.5
nvd
почти 9 лет назад
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.
CVSS3: 5.5
debian
почти 9 лет назад
Apache Karaf before 4.0.10 enables a shutdown port on the loopback int ...
EPSS
Процентиль: 50%
0.00697
Низкий
2.1 Low
CVSS2