CVE-2017-15701

Severity
7.5HIGH
EPSS
2.3%
top 15.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1
Latest updateOct 19

Description

In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Mavenorg.apache.qpid:qpid-broker6.1.06.1.5
NVDapache/qpid_broker-j6.1.06.1.4
CVEListV5apache_software_foundation/apache_qpid_broker-j6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4

🔴Vulnerability Details

3
GHSA
Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption2018-10-19
OSV
Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption2018-10-19
CVEList
CVE-2017-15701: In Apache Qpid Broker-J versions 62017-12-01
CVE-2017-15701 (HIGH CVSS 7.5) | In Apache Qpid Broker-J versions 6. | cvebase.io