A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.
2021-06-16T12:15:12.617
2024-11-21T06:03:58.773
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | cxf | < 3.3.11 | Yes |
Application | apache | cxf | < 3.4.4 | Yes |
Application | apache | tomee | 8.0.6 | Yes |
Application | oracle | business_intelligence | 5.5.0.0.0 | Yes |
Application | oracle | business_intelligence | 5.9.0.0.0 | Yes |
Application | oracle | business_intelligence | 12.2.1.3.0 | Yes |
Application | oracle | business_intelligence | 12.2.1.4.0 | Yes |
Application | oracle | communications_element_manager | 8.2.2 | Yes |
Operating System | oracle | communications_messaging_server | 8.1 | Yes |