Red Hat Data Grid
cpe:2.3:a:redhat:data_grid:*:*:*:*:*:*:*
- < 8
A buffer leak vulnerability has been identified in the Infinispan component of Red Hat Data Grid. This issue arises in the REST compare API, where continuous requests containing large POST data can cause a buffer leak and result in an OutOfMemoryError. Although the REST endpoint requires authentication by default, allowing only authenticated users to exploit this vulnerability, it can still be used to mount a denial-of-service attack.
Exploitation of this vulnerability can cause a denial-of-service condition by exhausting available memory resources, leading to application crashes or unresponsiveness.
The vulnerability can be reproduced by sending continuous POST requests with large payloads to the REST compare API endpoint. This can be done using tools that automate HTTP requests, such as curl or Postman, or by writing a script that sends repeated requests with the desired data size. Monitor the application for 'OutOfMemoryError' messages, which indicate that the buffer leak is causing memory exhaustion.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.