Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Java | — | Upgrade to Apple Java version 1.6.0.31 | Apr 4, 2012 | Dec 29, 2011 |
| Centos_linux | — | Upgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-develUpgrade java-1.6.0-openjdk-src | Dec 1, 2016 | Dec 29, 2011 |
| Gentoo Linux | — | Upgrade dev-java/oracle-jre-bin.Upgrade dev-java/oracle-jdk-bin.Upgrade app-emulation/emul-linux-x86-java.Upgrade dev-java/icedtea-bin.Upgrade dev-java/sun-jdk.Upgrade dev-java/sun-jre-bin. | Oct 30, 2017 | Dec 29, 2011 |
| Hpux | — | Update Jre70.JRE70-COM to the latest versionUpdate Jre70.JRE70-IPF32 to the latest versionUpdate Jdk70.JDK70-IPF64 to the latest versionUpdate Jre70.JRE70-IPF64-HS to the latest versionUpdate Jre70.JRE70-IPF32-HS to the latest versionUpdate Jdk70.JDK70-IPF32 to the latest versionUpdate Jdk70.JDK70-COM to the latest versionUpdate Jre70.JRE70-IPF64 to the latest versionUpdate Jdk70.JDK70-DEMO to the latest version | Aug 11, 2017 | Dec 29, 2011 |
| Jre Vuln | — | Upgrade to the latest version of Oracle Java | Feb 20, 2012 | Dec 29, 2011 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 14736139 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 14736141 for version 12.1.1.0.0.Apply the Patch Set Update (PSU) 14736140 for version 10.3.5.0.0. | Apr 3, 2018 | Dec 29, 2011 |
| Oracle_linux | — | Upgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdk-devel | Oct 16, 2024 | Dec 30, 2011 |
| Suse | — | Upgrade java-1_7_0-openjdkUpgrade java-1_7_0-openjdk-develUpgrade java-1_7_0-openjdk-demoUpgrade java-1_7_0-openjdk-headless | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade openjdk-6-jre-headlessUpgrade icedtea-6-jre-jamvmUpgrade icedtea-6-jre-cacaoUpgrade openjdk-6-jre-libUpgrade openjdk-6-jreUpgrade openjdk-6-jre-zero | Nov 8, 2024 | Dec 30, 2011 |
| Vmsa 2012 0013 | — | Apply ESX400-201209401-SG | Sep 17, 2012 | Dec 29, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub