Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3171

Опубликовано: 05 окт. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.

Дополнительная информация

Статус:

Important
Дефект:
CWE-789
https://bugzilla.redhat.com/show_bug.cgi?id=2213639eap-7: heap exhaustion via deserialization

EPSS

Процентиль: 40%
0.0018
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.

CVSS3: 7.5
github
около 2 лет назад

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость компонентов Hashtable и HashMap платформы Red Hat JBoss Enterprise Application Platform, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 40%
0.0018
Низкий

7.5 High

CVSS3