4.3
CVSSv2

CVE-2014-0086

Published: 31/03/2014 Updated: 16/12/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote malicious users to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat richfaces 5.0.0

redhat jboss web framework kit 2.5.0

redhat richfaces 4.3.5

redhat richfaces 4.3.4

Vendor Advisories

It was found that certain malformed requests caused RichFaces to leak memory A remote, unauthenticated attacker could use this flaw to send a large number of malformed requests to a RichFaces application that uses the Atmosphere framework, leading to a denial of service (excessive memory consumption) on the application server ...