Description
readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
5GHSASpring Framework Inefficient Regular Expression Complexity↗2022-05-02 ▶ OSVSpring Framework Inefficient Regular Expression Complexity↗2022-05-02 ▶ GHSAGHSA-h2mv-7266-r4gv: readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1↗2022-04-29 ▶ CVEListCVE-2009-1190: Algorithmic complexity vulnerability in the java↗2009-04-27 ▶ CVEListCVE-2004-2540: readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1↗2005-11-16 ▶ 📋Vendor Advisories
1Red HatSpring Framework Remote Denial of Service vulnerability↗2009-04-22 ▶ 💬Community
1BugzillaCVE-2009-1190 Spring Framework Remote Denial of Service vulnerability↗2009-04-22 ▶