CVE-2009-1190
published 2009-04-27CVE-2009-1190: Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.80%
84.8th percentile
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Framework Remote Denial of Service vulnerability
vendor_redhat·2009-04-22·CVSS 5.0
CVE-2009-1190 [MEDIUM] Spring Framework Remote Denial of Service vulnerability
Spring Framework Remote Denial of Service vulnerability
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
Statement: This flaw affected JBoss Enterprise BRMS Platform 5.1.0 when run on Sun JDK 1.5.x. It was resolved in JBoss Enterprise BRMS Platform 5.2.0, both by updating spring and by dropping support for Sun JDK 1.5.x.
GHSA
Spring Framework Inefficient Regular Expression Complexity
ghsa·2022-05-02·CVSS 5.0
CVE-2009-1190 [MEDIUM] CWE-1333 Spring Framework Inefficient Regular Expression Complexity
Spring Framework Inefficient Regular Expression Complexity
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
OSV
Spring Framework Inefficient Regular Expression Complexity
osv·2022-05-02·CVSS 5.0
CVE-2009-1190 [MEDIUM] Spring Framework Inefficient Regular Expression Complexity
Spring Framework Inefficient Regular Expression Complexity
Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/34892http://www.packetstormsecurity.org/hitb06/DAY_1_-_Marc_Schoenefeld_-_Pentesting_Java_J2EE.pdfhttp://www.securityfocus.com/archive/1/502926/100/0/threadedhttp://www.springsource.com/securityadvisoryhttps://bugzilla.redhat.com/show_bug.cgi?id=497161https://exchange.xforce.ibmcloud.com/vulnerabilities/50083http://secunia.com/advisories/34892http://www.packetstormsecurity.org/hitb06/DAY_1_-_Marc_Schoenefeld_-_Pentesting_Java_J2EE.pdfhttp://www.securityfocus.com/archive/1/502926/100/0/threadedhttp://www.springsource.com/securityadvisoryhttps://bugzilla.redhat.com/show_bug.cgi?id=497161https://exchange.xforce.ibmcloud.com/vulnerabilities/50083
2009-04-27
Published