[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-7246Date: (C)2014-11-20   (M)2023-12-22


The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a denial of service (infinite loop) via a crafted cookie in a request.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.5
Exploit Score: 6.8
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
JVN#65559247
JVNDB-2014-000129
http://sources.forgerock.org/changelog/openam/?cs=11248
https://forgerock.org/2014/11/openam-security-advisory-201404/

CPE    10
cpe:/a:forgerock:openam:10.0.1
cpe:/a:forgerock:openam:9.5.3
cpe:/a:forgerock:openam:10.0.2
cpe:/a:forgerock:openam:9.5.5
...
CWE    1
CWE-20

© SecPod Technologies