CVE-2021-28165
01.04.2021, 15:15
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.Enginsight
| Vendor | Product | Version |
|---|---|---|
| eclipse | jetty | 7.2.2 ≤ 𝑥 < 9.4.39 |
| eclipse | jetty | 10.0.0 ≤ 𝑥 < 10.0.2 |
| eclipse | jetty | 11.0.0 ≤ 𝑥 < 11.0.2 |
| oracle | autovue_for_agile_product_lifecycle_management | 21.0.2 |
| oracle | communications_cloud_native_core_policy | 1.14.0 |
| oracle | communications_element_manager | 8.2.2 |
| oracle | communications_services_gatekeeper | 7.0 |
| oracle | communications_session_report_manager | 8.0.0.0 ≤ 𝑥 ≤ 8.2.4.0 |
| oracle | communications_session_route_manager | 8.0.0.0 ≤ 𝑥 ≤ 8.2.4.0 |
| oracle | rest_data_services | 𝑥 < 21.3 |
| oracle | siebel_core_-_automation | 𝑥 ≤ 21.9 |
| jenkins | jenkins | 𝑥 < 2.277.3 |
| jenkins | jenkins | 𝑥 < 2.286 |
| netapp | cloud_manager | 𝑥 < 3.9.8 |
| netapp | e-series_performance_analyzer | 𝑥 < 3.0 |
| netapp | e-series_santricity_os_controller | 11.0.0 ≤ 𝑥 < 11.70.1 |
| netapp | e-series_santricity_storage | 𝑥 < 1.10 |
| netapp | e-series_santricity_web_services | 𝑥 < 5.1 |
| netapp | ontap_tools | 𝑥 < 9.10 |
| netapp | santricity_cloud_connector | - |
| netapp | santricity_web_services_proxy | 𝑥 < 5.1 |
| netapp | snapcenter | 𝑥 < 4.6 |
| netapp | storage_replication_adapter_for_clustered_data_ontap | 𝑥 < 9.10 |
| netapp | vasa_provider_for_clustered_data_ontap | 𝑥 < 9.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
- CWE-755 - Improper Handling of Exceptional ConditionsThe software does not handle or incorrectly handles an exceptional condition.
References