Oracle GlassFish Server 2.1.1 < 2.1.1.15 / 3.0.1 < 3.0.1.5 / 3.1.1 < 3.1.1.2 Hash Collision DoS

medium Nessus Plugin ID 58090

Synopsis

The remote web server is affected by a denial of service vulnerability.

Description

The version of GlassFish Server running on the remote host is affected by a denial of service vulnerability which can be triggered by specially crafted requests containing parameter values that cause hash collisions when computing the hash values for storage in a hash table.

Solution

Upgrade to GlassFish Server 2.1.1.15 / 3.0.1.5 / 3.1.1.2 or later.

See Also

http://www.nessus.org/u?11da589e

Plugin Details

Severity: Medium

ID: 58090

File Name: glassfish_cve-2011-5035.nasl

Version: 1.13

Type: remote

Family: Web Servers

Published: 2/22/2012

Updated: 7/12/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: cpe:/a:oracle:glassfish_server

Required KB Items: www/glassfish

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/18/2011

Vulnerability Publication Date: 10/18/2011

Reference Information

CVE: CVE-2011-5035

BID: 51194