// For flags

CVE-2014-0086

RichFaces: remote denial of service via memory exhaustion

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.

La función doFilter en webapp/PushHandlerFilter.java en JBoss RichFaces 4.3.4, 4.3.5 y 5.x permite a atacantes remotos causar una denegación de servicio (consumo de memoria y error de falta de memoria) a través de un número grande de solicitudes atmosphere push malformadas.

It was found that certain malformed requests caused RichFaces to leak memory. A remote, unauthenticated attacker could use this flaw to send a large number of malformed requests to a RichFaces application that uses the Atmosphere framework, leading to a denial of service (excessive memory consumption) on the application server.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-03 CVE Reserved
  • 2014-03-26 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redhat
Search vendor "Redhat"
Jboss Web Framework Kit
Search vendor "Redhat" for product "Jboss Web Framework Kit"
2.5.0
Search vendor "Redhat" for product "Jboss Web Framework Kit" and version "2.5.0"
-
Affected
Redhat
Search vendor "Redhat"
Richfaces
Search vendor "Redhat" for product "Richfaces"
4.3.4
Search vendor "Redhat" for product "Richfaces" and version "4.3.4"
-
Affected
Redhat
Search vendor "Redhat"
Richfaces
Search vendor "Redhat" for product "Richfaces"
4.3.5
Search vendor "Redhat" for product "Richfaces" and version "4.3.5"
-
Affected
Redhat
Search vendor "Redhat"
Richfaces
Search vendor "Redhat" for product "Richfaces"
5.0.0
Search vendor "Redhat" for product "Richfaces" and version "5.0.0"
alpha1
Affected
Redhat
Search vendor "Redhat"
Richfaces
Search vendor "Redhat" for product "Richfaces"
5.0.0
Search vendor "Redhat" for product "Richfaces" and version "5.0.0"
alpha2
Affected
Redhat
Search vendor "Redhat"
Richfaces
Search vendor "Redhat" for product "Richfaces"
5.0.0
Search vendor "Redhat" for product "Richfaces" and version "5.0.0"
alpha3
Affected