CVE-2011-5035
Summary
| CVE | CVE-2011-5035 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-12-30 01:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Glassfish Server | 2.1.1 | All | All | All |
| Application | Oracle | Glassfish Server | 3.0.1 | All | All | All |
| Application | Oracle | Glassfish Server | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| '[security bulletin] HPSBUX02784 SSRT100871 rev.1 - HP-UX Running Java, Remote Unauthorized Access, D' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Oracle Critical Patch Update - January 2013 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Oracle Critical Patch Update - April 2012 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| oCERT.org - oCERT Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.ocert.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| '[security bulletin] HPSBUX02757 SSRT100779 rev.2 - HP-UX Running Java, Remote Unauthorized Access, D' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| HashCollision-DOS-POC/HashtablePOC.py at master · FireFart/HashCollision-DOS-POC · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| VU#903934 - Hash table implementations vulnerable to algorithmic complexity attacks | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Security Advisory SA48074 - Hitachi Cosminexus Products Java Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[security bulletin] HPSBMU02799 SSRT100867 rev.1 - HP Network Node Manager i (NNMi) v9.0x Running JD' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Security Advisory SA48950 - Red Hat update for java-1.6.0-ibm - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Oracle Critical Patch Update - January 2012 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [security-announce] SUSE-SU-2012:0603-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Gentoo Linux Documentation -- IcedTea JDK: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Support / Security / Advisories / / MDVSA-2013:150 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[security bulletin] HPSBMU02797 SSRT100867 rev.1 - HP Network Node Manager i (NNMi) v9.1x Running JD' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[security bulletin] HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Debian -- Security Information -- DSA-2420-1 openjdk-6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Best 7 Best Internet Security Software in 2019 | af854a3a-2127-422b-91ae-364da2661108 | www.nruns.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.