Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17950
HistoryMay 02, 2019 - 6:10 a.m.

Denial Of Service (DoS)

2019-05-0206:10:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.007

Percentile

80.4%

Java SE and Java SE Embedded are vulnerable to denial of service(Dos) attacks. This occurs in JAXP component of OpenJDK which fails to correctly enforce parse tree size limits when parsing XML documents. An attacker could use this flaw to crash the application via consuming an excessive amount of CPU and memory.