CVE-2014-0109
published 2014-05-08CVE-2014-0109: Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.64%
88.4th percentile
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | <= 2.6.13 | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
| apache | cxf | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Uncontrolled Resource Consumption in Apache CXF
osv·2022-05-13
CVE-2014-0109 [MEDIUM] Uncontrolled Resource Consumption in Apache CXF
Uncontrolled Resource Consumption in Apache CXF
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
GHSA
Uncontrolled Resource Consumption in Apache CXF
ghsa·2022-05-13
CVE-2014-0109 [MEDIUM] CWE-400 Uncontrolled Resource Consumption in Apache CXF
Uncontrolled Resource Consumption in Apache CXF
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
Red Hat
CXF: HTML content posted to SOAP endpoint could cause OOM errors
vendor_redhat·2014-05-01·CVSS 4.3
CVE-2014-0109 [MEDIUM] CWE-770 CXF: HTML content posted to SOAP endpoint could cause OOM errors
CXF: HTML content posted to SOAP endpoint could cause OOM errors
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.
A denial of service flaw was found in the way Apache CXF created error messages for certain POST requests. A remote attacker could send a specially crafted request which, when processed by an application using Apache CXF, could consume an excessive amount of memory on the system, possibly triggering an Out Of Memory (OOM) error.
Package: cxf (OpenShift Enterprise 1) - Will not fix
Package: cxf (Red Hat BPM Suite 6) - Affected
Package: cxf (Red Hat JBoss BRMS 5) - Will not fix
Package: cxf (Red Hat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors [fedora-all]
bugzilla·2014-05-08·CVSS 4.3
CVE-2014-0109 [MEDIUM] CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors [fedora-all]
CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please
Bugzilla
CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors
bugzilla·2014-05-02·CVSS 4.3
CVE-2014-0109 [MEDIUM] CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors
CVE-2014-0109 Apache CXF: HTML content posted to SOAP endpoint could cause OOM errors
If content is posted to a SOAP endpoint with Content-Type text/html, CXF
creates an error message based on the input. This could potentially cause a
Out Of Memory (OOM) error on a large input, leading to a possible Denial of
Service attack.
Affected versions:
Apach CXF 2.6.x < 2.6.14
Apach CXF 2.7.x < 2.7.11
References:
http://cxf.apache.org/security-advisories.data/CVE-2014-0109.txt.asc
Upstream fix:
https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=commit;h=f8ed98e684c1a67a77ae8726db05a04a4978a445
Discussion:
Created cxf tracking bugs for this issue:
Affects: fedora-all [bug 1095542]
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.2.4
http://rhn.redhat.com/errata/RHSA-2014-1351.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://www.securitytracker.com/id/1030201https://cxf.apache.org/security-advisories.data/CVE-2014-0109.txt.asc?version=1&modificationDate=1398873370740&api=v2https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3Ehttp://rhn.redhat.com/errata/RHSA-2014-1351.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://www.securitytracker.com/id/1030201https://cxf.apache.org/security-advisories.data/CVE-2014-0109.txt.asc?version=1&modificationDate=1398873370740&api=v2https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e%40%3Ccommits.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4%40%3Ccommits.cxf.apache.org%3E
2014-05-08
Published