Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade jettisonUpgrade jettison-javadoc | Feb 8, 2024 | Sep 16, 2022 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | Mar 19, 2024 |
| Debian | — | Upgrade libjettison-java | Jan 4, 2023 | Sep 16, 2022 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34890864 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 34883781 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 34883826 for version 12.2.1.4.0. | Jan 17, 2023 | Jan 17, 2023 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Sep 20, 2022 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Sep 16, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 16, 2022 |
| Suse | — | Upgrade jettisonUpgrade jettison-javadoc | Mar 20, 2023 | Sep 16, 2022 |
| Ubuntu | — | Upgrade libjettison-java (Ubuntu Pro)Upgrade libjettison-java | Jun 20, 2023 | Sep 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub