Apache Neethi Circular Policy Reference Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability exists in Apache Neethi versions prior to 3.2.2 due to improper detection of circular references in WS-Policy documents. This flaw allows an attacker to create policy documents with circular references that can cause the policy normalization process to enter an infinite loop or create excessive recursion. This behavior can lead to a stack overflow or cause the application to hang.
Impact
Exploitation of this vulnerability can cause a stack overflow or application hang, leading to a denial-of-service condition.
Remediation
Users are advised to upgrade to Apache Neethi version 3.2.2 or later, which addresses this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
