Oracle GlassFish Server 2.1.1 < 2.1.1.15 / 3.0.1 < 3.0.1.5 / 3.1.1 < 3.1.1.2 Hash Collision DoS

Medium Nessus Plugin ID 58090

Synopsis

The remote web server is affected by a denial of service vulnerability.

Description

The version of GlassFish Server running on the remote host is affected by a denial of service vulnerability which can be triggered by specially crafted requests containing parameter values that cause hash collisions when computing the hash values for storage in a hash table.

Solution

Upgrade to GlassFish Server 2.1.1.15 / 3.0.1.5 / 3.1.1.2 or later.

See Also

http://www.nessus.org/u?11da589e

Plugin Details

Severity: Medium

ID: 58090

File Name: glassfish_cve-2011-5035.nasl

Version: 1.13

Type: remote

Family: Web Servers

Published: 2012/02/22

Updated: 2018/07/12

Dependencies: 55930

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:glassfish_server

Required KB Items: www/glassfish

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2011/10/18

Vulnerability Publication Date: 2011/10/18

Reference Information

CVE: CVE-2011-5035

BID: 51194