CVE-2021-28165
01.04.2021, 15:15
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.Enginsight
Vendor | Product | Version |
---|---|---|
eclipse | jetty | 7.2.2 ≤ 𝑥 < 9.4.39 |
eclipse | jetty | 10.0.0 ≤ 𝑥 < 10.0.2 |
eclipse | jetty | 11.0.0 ≤ 𝑥 < 11.0.2 |
oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
oracle | communications_cloud_native_core_policy | 1.14.0 |
oracle | communications_element_manager | 8.2.2 |
oracle | communications_services_gatekeeper | 7.0 |
oracle | communications_session_report_manager | 8.0.0.0 ≤ 𝑥 ≤ 8.2.4.0 |
oracle | communications_session_route_manager | 8.0.0.0 ≤ 𝑥 ≤ 8.2.4.0 |
oracle | rest_data_services | 𝑥 < 21.3 |
oracle | siebel_core_-_automation | 𝑥 ≤ 21.9 |
jenkins | jenkins | 𝑥 < 2.277.3 |
jenkins | jenkins | 𝑥 < 2.286 |
netapp | cloud_manager | 𝑥 < 3.9.8 |
netapp | e-series_performance_analyzer | 𝑥 < 3.0 |
netapp | e-series_santricity_os_controller | 11.0.0 ≤ 𝑥 < 11.70.1 |
netapp | e-series_santricity_storage | 𝑥 < 1.10 |
netapp | e-series_santricity_web_services | 𝑥 < 5.1 |
netapp | ontap_tools | 𝑥 < 9.10 |
netapp | santricity_cloud_connector | - |
netapp | santricity_web_services_proxy | 𝑥 < 5.1 |
netapp | snapcenter | 𝑥 < 4.6 |
netapp | storage_replication_adapter_for_clustered_data_ontap | 𝑥 < 9.10 |
netapp | vasa_provider_for_clustered_data_ontap | 𝑥 < 9.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
- CWE-755 - Improper Handling of Exceptional ConditionsThe software does not handle or incorrectly handles an exceptional condition.
References