CVE-2011-5035

Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:glassfish_server:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:3.0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-12-30 01:55

Updated : 2024-02-28 11:41


NVD link : CVE-2011-5035

Mitre link : CVE-2011-5035

CVE.ORG link : CVE-2011-5035


JSON object : View

Products Affected

oracle

  • glassfish_server
CWE
CWE-20

Improper Input Validation