http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade httpcomponents-clientUpgrade commons-httpclient | Jul 30, 2024 | Oct 27, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade httpcomponents-client | Dec 4, 2019 | Oct 27, 2015 |
| Huawei Euleros 2_0_sp3 | — | Upgrade jakarta-commons-httpclient | Sep 25, 2019 | Oct 27, 2015 |
| Huawei Euleros 2_0_sp5 | — | Upgrade jakarta-commons-httpclient | Feb 24, 2020 | Oct 27, 2015 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Jul 2, 2021 | Oct 27, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 3, 2015 |
| Suse | — | Upgrade apache-commons-httpclient-demoUpgrade apache-commons-httpclient-javadocUpgrade apache-commons-httpclient-manualUpgrade apache-commons-httpclient | Nov 5, 2020 | Oct 27, 2015 |
| Ubuntu | — | Upgrade libcommons-httpclient-java | Nov 8, 2024 | Oct 27, 2015 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 27, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub