Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2094

Опубликовано: 17 фев. 2016
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability.

A read-timeout flaw was found in the HTTPS NIO Connector handling of SSL handshakes. A remote, unauthenticated attacker could create a socket and cause a thread to remain occupied indefinitely so long as the socket remained open (denial of service).

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1308465EAP: HTTPS NIO connector uses no timeout when reading SSL handshake from client

EPSS

Процентиль: 83%
0.01992
Низкий

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
nvd
почти 10 лет назад

The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability.

CVSS3: 7.5
github
больше 3 лет назад

The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability.

EPSS

Процентиль: 83%
0.01992
Низкий

5 Medium

CVSS2

Уязвимость CVE-2016-2094