CVE-2021-30468

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.53 % (77th)
0.53% Progress
Affected Products 5
Advisories 1

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thread getting stuck in an infinite loop, consuming CPU indefinitely. This issue affects Apache CXF versions prior to 3.4.4; Apache CXF versions prior to 3.3.11.

Weaknesses
CWE-400
Uncontrolled Resource Consumption
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2021-06-16 12:15:12
(3 years ago)
Updated Date
2023-11-07 03:33:02
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Cxf prior 3.3.11 version cpe:2.3:a:apache:cxf < 3.3.11
  Apache Cxf from 3.4.0 version and prior 3.4.4 version cpe:2.3:a:apache:cxf >= 3.4.0 < 3.4.4
  Apache Tomee 8.0.6 cpe:2.3:a:apache:tomee:8.0.6

Configuration #2

    CPE23 From Up To
  Oracle Business Intelligence 5.5.0.0.0 cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise
  Oracle Business Intelligence 5.9.0.0.0 cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise
  Oracle Business Intelligence 12.2.1.3.0 cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise
  Oracle Business Intelligence 12.2.1.4.0 cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise
  Oracle Communications Element Manager 8.2.2 cpe:2.3:a:oracle:communications_element_manager:8.2.2
  Oracle Communications Messaging Server 8.1 cpe:2.3:o:oracle:communications_messaging_server:8.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...