Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46737
HistoryMay 03, 2024 - 8:03 a.m.

Denial Of Service (DoS)

2024-05-0308:03:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
zope object database
vulnerability
denial of service
remote attackers
tcp connection

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.1 High

AI Score

Confidence

High

0.038 Low

EPSS

Percentile

91.9%

Zope Object Database (ZODB) is vulnerable to Denial Of Service (DoS). The vulnerability is due to a flaw that allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, resulting in unexpected return values for the accept function or specific errors such as ECONNABORTED, EAGAIN, or EWOULDBLOCK.

CPENameOperatorVersion
zodb3le3.10.0a1
zodb3le3.10.0a1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

7.1 High

AI Score

Confidence

High

0.038 Low

EPSS

Percentile

91.9%