Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability
BID:51194
Info
Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability
| Bugtraq ID: | 51194 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-5035 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2011 12:00AM |
| Updated: | Apr 13 2015 09:24PM |
| Credit: | Alexander Klink, n.runs AG and Julian Waumllde, Technische Universit Darmstadt |
| Vulnerable: |
VMWare ESX 4.1 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise Java 11 SP1 SuSE SUSE Linux Enterprise Java 10 SP4 SuSE Suse Linux Enterprise Desktop 11 SP1 for SP2 SuSE Suse Linux Enterprise Desktop 11 SP1 Sun JRE (Windows Production Release) 1.6 _17 Sun JRE (Windows Production Release) 1.6 _13 Sun JRE (Windows Production Release) 1.6 _12 Sun JRE (Windows Production Release) 1.6 _10 Sun JRE (Windows Production Release) 1.6 _07 Sun JRE (Windows Production Release) 1.6 _06 Sun JRE (Windows Production Release) 1.6 _05 Sun JRE (Windows Production Release) 1.6 _04 Sun JRE (Windows Production Release) 1.6 Sun JRE (Windows Production Release) 1.7 Sun JRE (Windows Production Release) 1.6.0_21 Sun JRE (Windows Production Release) 1.6.0_20 Sun JRE (Windows Production Release) 1.6.0_2 Sun JRE (Windows Production Release) 1.6.0_19 Sun JRE (Windows Production Release) 1.6.0_18 Sun JRE (Windows Production Release) 1.6.0_15 Sun JRE (Windows Production Release) 1.6.0_14 Sun JRE (Windows Production Release) 1.6.0_11 Sun JRE (Windows Production Release) 1.6.0_03 Sun JRE (Windows Production Release) 1.6.0_02 Sun JRE (Windows Production Release) 1.6.0_01 Sun JRE (Solaris Production Release) 1.6 _17 Sun JRE (Solaris Production Release) 1.6 _13 Sun JRE (Solaris Production Release) 1.6 _12 Sun JRE (Solaris Production Release) 1.6 _10 Sun JRE (Solaris Production Release) 1.6 _07 Sun JRE (Solaris Production Release) 1.6 _06 Sun JRE (Solaris Production Release) 1.6 _05 Sun JRE (Solaris Production Release) 1.6 _04 Sun JRE (Solaris Production Release) 1.6 Sun JRE (Solaris Production Release) 1.7 Sun JRE (Solaris Production Release) 1.6.0_21 Sun JRE (Solaris Production Release) 1.6.0_2 Sun JRE (Solaris Production Release) 1.6.0_19 Sun JRE (Solaris Production Release) 1.6.0_18 Sun JRE (Solaris Production Release) 1.6.0_15 Sun JRE (Solaris Production Release) 1.6.0_14 Sun JRE (Solaris Production Release) 1.6.0_11 Sun JRE (Solaris Production Release) 1.6.0_03 Sun JRE (Solaris Production Release) 1.6.0_02 Sun JRE (Solaris Production Release) 1.6.0_01 Sun JRE (Linux Production Release) 1.6 _17 Sun JRE (Linux Production Release) 1.6 _13 Sun JRE (Linux Production Release) 1.6 _12 Sun JRE (Linux Production Release) 1.6 _10 Sun JRE (Linux Production Release) 1.6 _07 Sun JRE (Linux Production Release) 1.6 _06 Sun JRE (Linux Production Release) 1.6 _05 Sun JRE (Linux Production Release) 1.6 _04 Sun JRE (Linux Production Release) 1.6 Sun JRE (Linux Production Release) 1.7 Sun JRE (Linux Production Release) 1.6.0_21 Sun JRE (Linux Production Release) 1.6.0_20 Sun JRE (Linux Production Release) 1.6.0_19 Sun JRE (Linux Production Release) 1.6.0_18 Sun JRE (Linux Production Release) 1.6.0_15 Sun JRE (Linux Production Release) 1.6.0_14 Sun JRE (Linux Production Release) 1.6.0_11 Sun JRE (Linux Production Release) 1.6.0_03 Sun JRE (Linux Production Release) 1.6.0_02 Sun JRE (Linux Production Release) 1.6.0_01 Sun JDK (Windows Production Release) 1.6 _17 Sun JDK (Windows Production Release) 1.6 _14 Sun JDK (Windows Production Release) 1.6 _13 Sun JDK (Windows Production Release) 1.6 _11 Sun JDK (Windows Production Release) 1.6 _10 Sun JDK (Windows Production Release) 1.6 _07 Sun JDK (Windows Production Release) 1.6 _06 Sun JDK (Windows Production Release) 1.6 _05 Sun JDK (Windows Production Release) 1.6 _04 Sun JDK (Windows Production Release) 1.6 Sun JDK (Windows Production Release) 1.6.0_21 Sun JDK (Windows Production Release) 1.6.0_20 Sun JDK (Windows Production Release) 1.6.0_19 Sun JDK (Windows Production Release) 1.6.0_18 Sun JDK (Windows Production Release) 1.6.0_15 Sun JDK (Windows Production Release) 1.6.0_03 Sun JDK (Windows Production Release) 1.6.0_02 Sun JDK (Windows Production Release) 1.6.0_01-b06 Sun JDK (Windows Production Release) 1.6.0_01 Sun JDK (Solaris Production Release) 1.6 _17 Sun JDK (Solaris Production Release) 1.6 _14 Sun JDK (Solaris Production Release) 1.6 _13 Sun JDK (Solaris Production Release) 1.6 _11 Sun JDK (Solaris Production Release) 1.6 _10 Sun JDK (Solaris Production Release) 1.6 _07 Sun JDK (Solaris Production Release) 1.6 _06 Sun JDK (Solaris Production Release) 1.6 _05 Sun JDK (Solaris Production Release) 1.6 _04 Sun JDK (Solaris Production Release) 1.6 _01-b06 Sun JDK (Solaris Production Release) 1.6 Sun JDK (Solaris Production Release) 1.6.0_21 Sun JDK (Solaris Production Release) 1.6.0_20 Sun JDK (Solaris Production Release) 1.6.0_19 Sun JDK (Solaris Production Release) 1.6.0_18 Sun JDK (Solaris Production Release) 1.6.0_15 Sun JDK (Solaris Production Release) 1.6.0_03 Sun JDK (Solaris Production Release) 1.6.0_02 Sun JDK (Solaris Production Release) 1.6.0_01 Sun JDK (Linux Production Release) 1.6 _17 Sun JDK (Linux Production Release) 1.6 _14 Sun JDK (Linux Production Release) 1.6 _13 Sun JDK (Linux Production Release) 1.6 _11 Sun JDK (Linux Production Release) 1.6 _10 Sun JDK (Linux Production Release) 1.6 _07 Sun JDK (Linux Production Release) 1.6 _06 Sun JDK (Linux Production Release) 1.6 _05 Sun JDK (Linux Production Release) 1.6 _04 Sun JDK (Linux Production Release) 1.6 _01-b06 Sun JDK (Linux Production Release) 1.6 _01 Sun JDK (Linux Production Release) 1.6 Sun JDK (Linux Production Release) 1.6.0_21 Sun JDK (Linux Production Release) 1.6.0_20 Sun JDK (Linux Production Release) 1.6.0_19 Sun JDK (Linux Production Release) 1.6.0_18 Sun JDK (Linux Production Release) 1.6.0_15 Sun JDK (Linux Production Release) 1.6.0_03 Sun JDK (Linux Production Release) 1.6.0_02 Sun JDK (Linux Production Release) 1.6.0 Update 7 Sun JDK (Linux Production Release) 1.6.0 Update 6 Sun JDK (Linux Production Release) 1.6.0 Update 5 Sun JDK (Linux Production Release) 1.6.0 Update 4 Sun JDK (Linux Production Release) 1.6.0 Update 3 Sun JDK (Linux Production Release) 1.6.0 Update 21 Sun JDK (Linux Production Release) 1.6.0 Update 20 Sun JDK (Linux Production Release) 1.6.0 Update 19 Sun JDK (Linux Production Release) 1.6.0 Update 18 Sun JDK (Linux Production Release) 1.6.0 Update 17 Sun JDK (Linux Production Release) 1.6.0 Update 16 Sun JDK (Linux Production Release) 1.6.0 Update 15 Sun JDK (Linux Production Release) 1.6.0 Update 14 Sun JDK (Linux Production Release) 1.6.0 Update 13 Sun JDK (Linux Production Release) 1.6.0 Update 12 Sun JDK (Linux Production Release) 1.6.0 Update 11 Sun JDK (Linux Production Release) 1.6.0 Update 10 Sun Java System Web Server 6.1 SP9 Sun Java System Web Server 6.1 SP8 Sun Java System Web Server 6.1 SP7 Sun Java System Web Server 6.1 SP6 Sun Java System Web Server 6.1 SP5 Sun Java System Web Server 6.1 SP4 Sun Java System Web Server 6.1 SP3 Sun Java System Web Server 6.1 SP2 Sun Java System Web Server 6.1 SP11 Sun Java System Web Server 6.1 SP10 Sun Java System Web Server 6.1 SP1 Sun Java System Web Server 6.1 Sun Java System Web Server 6.1 SP11 Sun Java System Web Server 6.1 SP10 Sun Java System Web Server 6.1 Sun Java System Application Server 8.2 Sun Java System Application Server 8.1 Sun iPlanet Web Server 7.0 S.u.S.E. openSUSE 11.4 Redhat Enterprise Linux WS Extras 4 Redhat Enterprise Linux Workstation Supplementary 6 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Server Supplementary 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Supplementary 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux ES Extras 4 Redhat Enterprise Linux Desktop Supplementary 6 Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS Extras 4 Redhat Enterprise Linux 5 Server Redhat Desktop Extras 4 Oracle Weblogic Server 12.1.1 0 Oracle Weblogic Server 10.3.6 0 Oracle Weblogic Server 10.3.3 Oracle Weblogic Server 9.2.4 Oracle Weblogic Server 11gR1 Oracle Weblogic Server 10.3.5.0 Oracle Weblogic Server 10.3.4 Oracle Weblogic Server 10.0.2 Oracle Virtual Desktop Infrastructure 3.3 Oracle Virtual Desktop Infrastructure 3.2 Oracle JRockit R28.2.2 Oracle JRockit R28.1.4 Oracle JRockit R28.1.3 Oracle JRockit R28.1.1 Oracle JRockit R28.0.1 Oracle JRockit R28.0.0 Oracle JRockit R27.7.1 Oracle JRockit R27.6.9 Oracle JRockit R27.6.8 Oracle JRockit R27.6.7 Oracle JRockit R27.6.6 Oracle JRockit R27.6.5 Oracle JRockit R27.6.4 Oracle JRockit R27.6.3 Oracle JRockit R27.6.2 Oracle JRockit R27.6.0-50 1.5.0 15 Oracle JRockit R27.6.0 Oracle JRockit R27.1.0 Oracle JRE (Windows Production Release) 1.7.0_2 Oracle JRE (Windows Production Release) 1.6.0_30 Oracle JRE (Windows Production Release) 1.6.0_28 Oracle JRE (Windows Production Release) 1.6.0_27 Oracle JRE (Windows Production Release) 1.6.0_26 Oracle JRE (Windows Production Release) 1.6.0_25 Oracle JRE (Windows Production Release) 1.6.0_24 Oracle JRE (Windows Production Release) 1.6.0_23 Oracle JRE (Windows Production Release) 1.6.0_22 Oracle JRE (Solaris Production Release) 1.7.0_2 Oracle JRE (Solaris Production Release) 1.6.0_30 Oracle JRE (Solaris Production Release) 1.6.0_28 Oracle JRE (Solaris Production Release) 1.6.0_27 Oracle JRE (Solaris Production Release) 1.6.0_26 Oracle JRE (Solaris Production Release) 1.6.0_25 Oracle JRE (Solaris Production Release) 1.6.0_24 Oracle JRE (Solaris Production Release) 1.6.0_23 Oracle JRE (Solaris Production Release) 1.6.0_22 Oracle JRE (Linux Production Release) 1.7.0_2 Oracle JRE (Linux Production Release) 1.6.0_30 Oracle JRE (Linux Production Release) 1.6.0_28 Oracle JRE (Linux Production Release) 1.6.0_27 Oracle JRE (Linux Production Release) 1.6.0_26 Oracle JRE (Linux Production Release) 1.6.0_25 Oracle JRE (Linux Production Release) 1.6.0_24 Oracle JRE (Linux Production Release) 1.6.0_23 Oracle JRE (Linux Production Release) 1.6.0_22 Oracle JDK (Windows Production Release) 1.7 Oracle JDK (Windows Production Release) 1.7.0_2 Oracle JDK (Windows Production Release) 1.6.0_30 Oracle JDK (Windows Production Release) 1.6.0_28 Oracle JDK (Windows Production Release) 1.6.0_27 Oracle JDK (Windows Production Release) 1.6.0_26 Oracle JDK (Windows Production Release) 1.6.0_25 Oracle JDK (Windows Production Release) 1.6.0_24 Oracle JDK (Windows Production Release) 1.6.0_23 Oracle JDK (Windows Production Release) 1.6.0_22 Oracle JDK (Solaris Production Release) 1.7 Oracle JDK (Solaris Production Release) 1.7.0_2 Oracle JDK (Solaris Production Release) 1.6.0_30 Oracle JDK (Solaris Production Release) 1.6.0_28 Oracle JDK (Solaris Production Release) 1.6.0_27 Oracle JDK (Solaris Production Release) 1.6.0_26 Oracle JDK (Solaris Production Release) 1.6.0_25 Oracle JDK (Solaris Production Release) 1.6.0_24 Oracle JDK (Solaris Production Release) 1.6.0_23 Oracle JDK (Solaris Production Release) 1.6.0_22 Oracle JDK (Linux Production Release) 1.7 Oracle JDK (Linux Production Release) 1.7.0_2 Oracle JDK (Linux Production Release) 1.6.0_30 Oracle JDK (Linux Production Release) 1.6.0_28 Oracle JDK (Linux Production Release) 1.6.0_27 Oracle JDK (Linux Production Release) 1.6.0_26 Oracle JDK (Linux Production Release) 1.6.0_25 Oracle JDK (Linux Production Release) 1.6.0_24 Oracle JDK (Linux Production Release) 1.6.0_23 Oracle JDK (Linux Production Release) 1.6.0_22 Oracle iPlanet WebServer 7.0 Oracle Glassfish Server 3.1.1 Oracle Glassfish Server 3.1 Oracle Glassfish Server 3.0.1 Oracle Glassfish Server 3.0 Oracle Glassfish Server 2.1.1 Oracle Glassfish Server 2.1 Oracle Glassfish Server 2.0 Oracle Glassfish Server 1.0 Ur1 Po1 Oracle Glassfish Server 1.0 Ur1 Oracle Glassfish Server 1.0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Communications Server 2.0 Oracle Application Server 10g 10.1.3 .5.0 R3 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 IBM Rational Synergy 7.2.0.2 IBM Rational Synergy 7.1.0.5 IBM Java SE 7.0 IBM Java SE 7 IBM Java SE 6.0.0 SR9-FP2 IBM Java SE 6.0.0 SR9 IBM Java SE 6.0 SR7 IBM Java SE 6.0 SR6 IBM Java SE 6.0 SR5 IBM Java SE 6.0 IBM Java SE 6 SR8 FP1 IBM Java SE 6 SR10 IBM Java SE 6 IBM JAVA IBM 64-bit SDK for z/OS 6.0 IBM JAVA IBM 31-bit SDK for z/OS 6.0 HP XP P9000 Performance Advisor 5.4.1 HP NonStop Server J6.0.14.01 HP NonStop Server J06.16 HP NonStop Server J06.15.01 HP NonStop Server J06.15 HP NonStop Server J06.14.02 HP NonStop Server J06.14 HP NonStop Server J06.13.01 HP NonStop Server J06.13 HP NonStop Server J06.12.00 HP NonStop Server J06.11.01 HP NonStop Server J06.11.00 HP NonStop Server J06.10.02 HP NonStop Server J06.10.01 HP NonStop Server J06.10.00 HP NonStop Server J06.09.04 HP NonStop Server J06.09.03 HP NonStop Server J06.09.02 HP NonStop Server J06.09.01 HP NonStop Server J06.09.00 HP NonStop Server J06.08.04 HP NonStop Server J06.08.03 HP NonStop Server J06.08.02 HP NonStop Server J06.08.01 HP NonStop Server J06.08.00 HP NonStop Server J06.07.02 HP NonStop Server J06.07.01 HP NonStop Server J06.07.00 HP NonStop Server J06.06.03 HP NonStop Server J06.06.02 HP NonStop Server J06.06.01 HP NonStop Server J06.06.00 HP NonStop Server J06.05.02 HP NonStop Server J06.05.01 HP NonStop Server J06.05.00 HP NonStop Server J06.04.02 HP NonStop Server J06.04.01 HP NonStop Server J06.04.00 HP NonStop Server H06.27 HP NonStop Server H06.26.01 HP NonStop Server H06.26 HP NonStop Server H06.25.01 HP NonStop Server H06.25 HP NonStop Server H06.24.01 HP NonStop Server H06.24 HP NonStop Server H06.23 HP NonStop Server H06.22.01 HP NonStop Server H06.22.00 HP NonStop Server H06.21.02 HP NonStop Server H06.21.01 HP NonStop Server H06.21.00 HP NonStop Server H06.20.03 HP NonStop Server H06.20.02 HP NonStop Server H06.20.01 HP NonStop Server H06.20.00 HP NonStop Server H06.19.03 HP NonStop Server H06.19.02 HP NonStop Server H06.19.01 HP NonStop Server H06.19.00 HP NonStop Server H06.18.02 HP NonStop Server H06.18.01 HP NonStop Server H06.18.00 HP NonStop Server H06.17.03 HP NonStop Server H06.17.02 HP NonStop Server H06.17.01 HP NonStop Server H06.17.00 HP NonStop Server H06.16.02 HP NonStop Server H06.16.01 HP NonStop Server H06.16.00 HP NonStop Server H06.15.02 HP NonStop Server H06.15.01 HP NonStop Server H06.15.00 HP NonStop Server 6 HP Network Node Manager i 9.1 HP JDK and JRE 7.0 HP HP-UX B.11.31 HP HP-UX B.11.11 Hitachi uCosminexus Service Platform - Messaging 0 Hitachi uCosminexus Service Platform 0 Hitachi uCosminexus Service Architect 0 Hitachi uCosminexus Primary Server Base 0 Hitachi uCosminexus Operator 0 Hitachi uCosminexus Developer Standard 0 Hitachi uCosminexus Developer Professional for Plug-in 0 Hitachi uCosminexus Developer Professional 0 Hitachi uCosminexus Developer Light 0 Hitachi uCosminexus Developer 01 0 Hitachi uCosminexus Client for Plug-in 0 Hitachi uCosminexus Client 0 Hitachi uCosminexus Application Server Standard-R 0 Hitachi uCosminexus Application Server Standard 0 Hitachi uCosminexus Application Server Smart Edition 0 Hitachi uCosminexus Application Server Light 0 Hitachi uCosminexus Application Server Enterprise 09-80 (Windows(x64)) Hitachi Processing Kit for XML 0 Hitachi Cosminexus Studio - Web Edition 0 Hitachi Cosminexus Studio - Standard Edition 0 Hitachi Cosminexus Studio 0 Hitachi Cosminexus Primary Server Base 0 Hitachi Cosminexus Developer Standard 0 Hitachi Cosminexus Developer Professional 0 Hitachi Cosminexus Developer no version 0 Hitachi Cosminexus Developer Light 0 Hitachi Cosminexus Client 0 Hitachi Cosminexus Application Server Standard 0 Hitachi Cosminexus Application Server no version 0 Hitachi Cosminexus Application Server Enterprise 0 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.0 Avaya Proactive Contact 4.2.2 Avaya Proactive Contact 4.2.1 Avaya Proactive Contact 4.2 Avaya Messaging Storage Server 5.2.8 Avaya Messaging Storage Server 5.2.2 Avaya Messaging Storage Server 5.2 SP3 Avaya Messaging Storage Server 5.2 SP2 Avaya Messaging Storage Server 5.2 SP1 Avaya Messaging Storage Server 5.2 Avaya Messaging Application Server 5.2 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.4 Avaya Message Networking 5.2.3 Avaya Message Networking 5.2.2 Avaya Message Networking 5.2 SP1 Avaya Message Networking 5.2 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP2 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya IR 4.0 Avaya IQ 5.2 Avaya IQ 5.1.1 Avaya IQ 5.1 Avaya IQ 5 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya Communication Manager 5.1.2 Avaya Communication Manager 5.2 Avaya Communication Manager 5.1 Avaya Communication Manager 5.0 SP3 Avaya Communication Manager 5.0 Avaya Call Management System R 16.0 Avaya Call Management System R 15.0 Avaya Aura System Platform 6.0.2 Avaya Aura System Platform 6.0.1 Avaya Aura System Platform 6.0 SP3 Avaya Aura System Platform 6.0 SP2 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.7.3 Apple Mac OS X Server 10.7.2 Apple Mac OS X Server 10.7.1 Apple Mac OS X Server 10.7 Apple Mac OS X Server 10.6.8 Apple Mac OS X Server 10.6.7 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.6 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.7.3 Apple Mac OS X 10.7.2 Apple Mac OS X 10.7.1 Apple Mac OS X 10.7 Apple Mac OS X 10.6.8 Apple Mac OS X 10.6.7 Apple Mac OS X 10.6 |
| Not Vulnerable: |
IBM Rational Synergy 7.2.0.3 IBM Rational Synergy 7.1.0.6 IBM Java SE 7 SR1 HP XP P9000 Performance Advisor 5.5.1 HP JDK and JRE 7.0.1 Avaya Conferencing Standard Edition 7.0 |
Discussion
Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability
Oracle GlassFish Server is prone to a denial-of-service vulnerability.
An attacker can exploit this issue by sending specially crafted forms in HTTP POST requests.
Oracle GlassFish Server 3.1.1 and prior versions are vulnerable.
Oracle GlassFish Server is prone to a denial-of-service vulnerability.
An attacker can exploit this issue by sending specially crafted forms in HTTP POST requests.
Oracle GlassFish Server 3.1.1 and prior versions are vulnerable.
Exploit / POC
Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.6.8
Apple Mac OS X Server 10.6.6
Solution:
Updates are available. Please see the references for more information.
Apple Mac OS X 10.6.8
-
Apple JavaForMacOSX10.6.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.6
-
Apple JavaForMacOSX10.6.dmg
http://www.apple.com/support/downloads/
References
Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability
References:
References:
- HPSBUX02784 SSRT100871 (HP)
- IBM Java Update Oracle February 14 2012 CPU (IBM)
- IBM Oracle February 14 2012 CPU (IBM)
- n.runs-SA-2011.004 28-Dec-2011 (n.runs AG)
- Oracle GlassFish Server (Oracle)
- Oracle Security Alert for CVE-2011-5035 (Oracle)
- PM59971: GEN APAR: 31-BIT JAVA FOR Z/OS SDK 6 SERVICE REFRESH (SR10 FP1) THE PTF (IBM)
- PM59978: GEN APAR: 64-BIT JAVA FOR Z/OS SDK 6 SERVICE REFRESH (SR10 FP1) THE PTF (IBM)
- #2011-003 multiple implementations denial-of-service via hash algorithm collisio (oCERT)
- ASA-2012-128:Oracle Java Critical Update Combined CVEs (February 2012) (Avaya)
- ASA-2012-154 java-1.6.0-openjdk security update (RHSA-2012-0322) (Avaya)
- ASA-2012-169 java-1.6.0-sun security update (RHSA-2012-0139) (Avaya)
- HPSBUX02757 SSRT100779 rev.1 - HP-UX Running Java, Remote Unauthorized Access, D (HP)
- HPSBUX02757 SSRT100779 rev.2 - HP-UX Running Java, Remote Unauthorized Access, D (HP)
- HS12-007 Multiple Vulnerabilities in Cosminexus (Hitachi)
- Oracle Critical Patch Update Advisory - April 2012 (Oracle)
- Oracle Critical Patch Update Advisory - January 2012 (Oracle)
- Oracle Java SE Critical Patch Update Advisory - February 2012 (Oracle)