4.3
CVE-2024-47554
- EPSS 1.24%
- Veröffentlicht 03.10.2024 12:15:02
- Zuletzt bearbeitet 10.07.2025 21:10:32
- Erkennungen
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Commons Io Version >= 2.0 < 2.14.0
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ E-series Santricity Unified Manager Version -
Netapp ≫ E-series Santricity Web Services Proxy Version -
Netapp ≫ Ontap Tools Version 9 SwPlatform vmware_vsphere
Netapp ≫ Ontap Tools Version 10 SwPlatform vmware_vsphere
Netapp ≫ Santricity Storage Plugin Version - SwPlatform vcenter
Netapp ≫ Snapcenter Version -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.24% | 0.656 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1
http://www.openwall.com/lists/oss-security/2024/10/03/2
https://security.netapp.com/advisory/ntap-20250131-0010/