4.3
CVSSv2

CVE-2014-0109

Published: 08/05/2014 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache CXF prior to 2.6.14 and 2.7.x prior to 2.7.11 allows remote malicious users to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.

Vulnerable Product Search on Vulmon Subscribe to Product

apache cxf 2.7.3

apache cxf 2.7.5

apache cxf 2.7.10

apache cxf 2.7.6

apache cxf 2.7.9

apache cxf 2.7.0

apache cxf 2.7.4

apache cxf 2.7.1

apache cxf 2.7.8

apache cxf 2.7.7

apache cxf 2.7.2

apache cxf 2.5.2

apache cxf 2.5.9

apache cxf 2.4.6

apache cxf 2.6.8

apache cxf 2.6.0

apache cxf 2.5.3

apache cxf 2.4.0

apache cxf 2.4.3

apache cxf 2.6.12

apache cxf 2.5.7

apache cxf 2.4.4

apache cxf 2.6.2

apache cxf 2.4.2

apache cxf 2.5.0

apache cxf 2.5.1

apache cxf 2.5.5

apache cxf 2.6.9

apache cxf 2.5.8

apache cxf 2.6.5

apache cxf 2.6.10

apache cxf 2.6.6

apache cxf 2.6.3

apache cxf 2.4.1

apache cxf 2.5.6

apache cxf 2.4.7

apache cxf 2.6.4

apache cxf 2.4.5

apache cxf 2.6.11

apache cxf 2.6.1

apache cxf

apache cxf 2.5.4

apache cxf 2.6.7

Vendor Advisories

A denial of service flaw was found in the way Apache CXF created error messages for certain POST requests A remote attacker could send a specially crafted request which, when processed by an application using Apache CXF, could consume an excessive amount of memory on the system, possibly triggering an Out Of Memory (OOM) error ...