Contact Us
SECURITY BLOG SECURITY DASHBOARD PARTNERS PRODUCTS JOBS SERVICES COMPANY HOME
Network Security Consulting Advisories Article

Oracle GlassFish Server Hash Collision Denial Of Service Vulnerability

http://www.securityfocus.com/bid/51194

Security Info

Bugtraq ID: 51194
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2011-5035
Remote: Yes
Local: No
Published: Dec 29 2011 12:00AM
Updated: Feb 15 2012 07:00AM
Credit: Alexander Klink, n.runs AG and Julian Wälde, Technische Universität Darmstadt
Vulnerable: Sun JRE (Windows Production Release) 1.6 _17
Sun JRE (Windows Production Release) 1.6 _13
Sun JRE (Windows Production Release) 1.6 _12
Sun JRE (Windows Production Release) 1.6 _10
Sun JRE (Windows Production Release) 1.6 _07
Sun JRE (Windows Production Release) 1.6 _06
Sun JRE (Windows Production Release) 1.6 _05
Sun JRE (Windows Production Release) 1.6 _04
Sun JRE (Windows Production Release) 1.6
Sun JRE (Windows Production Release) 1.7.0_2
Sun JRE (Windows Production Release) 1.7
Sun JRE (Windows Production Release) 1.6.0_30
Sun JRE (Windows Production Release) 1.6.0_28
Sun JRE (Windows Production Release) 1.6.0_27
Sun JRE (Windows Production Release) 1.6.0_26
Sun JRE (Windows Production Release) 1.6.0_25
Sun JRE (Windows Production Release) 1.6.0_24
Sun JRE (Windows Production Release) 1.6.0_23
Sun JRE (Windows Production Release) 1.6.0_22
Sun JRE (Windows Production Release) 1.6.0_21
Sun JRE (Windows Production Release) 1.6.0_20
Sun JRE (Windows Production Release) 1.6.0_2
Sun JRE (Windows Production Release) 1.6.0_19
Sun JRE (Windows Production Release) 1.6.0_18
Sun JRE (Windows Production Release) 1.6.0_15
Sun JRE (Windows Production Release) 1.6.0_14
Sun JRE (Windows Production Release) 1.6.0_11
Sun JRE (Windows Production Release) 1.6.0_03
Sun JRE (Windows Production Release) 1.6.0_02
Sun JRE (Windows Production Release) 1.6.0_01
Sun JRE (Solaris Production Release) 1.6 _17
Sun JRE (Solaris Production Release) 1.6 _13
Sun JRE (Solaris Production Release) 1.6 _12
Sun JRE (Solaris Production Release) 1.6 _10
Sun JRE (Solaris Production Release) 1.6 _07
Sun JRE (Solaris Production Release) 1.6 _06
Sun JRE (Solaris Production Release) 1.6 _05
Sun JRE (Solaris Production Release) 1.6 _04
Sun JRE (Solaris Production Release) 1.6
Sun JRE (Solaris Production Release) 1.7.0_2
Sun JRE (Solaris Production Release) 1.7
Sun JRE (Solaris Production Release) 1.6.0_30
Sun JRE (Solaris Production Release) 1.6.0_28
Sun JRE (Solaris Production Release) 1.6.0_27
Sun JRE (Solaris Production Release) 1.6.0_26
Sun JRE (Solaris Production Release) 1.6.0_25
Sun JRE (Solaris Production Release) 1.6.0_24
Sun JRE (Solaris Production Release) 1.6.0_23
Sun JRE (Solaris Production Release) 1.6.0_22
Sun JRE (Solaris Production Release) 1.6.0_21
Sun JRE (Solaris Production Release) 1.6.0_2
Sun JRE (Solaris Production Release) 1.6.0_19
Sun JRE (Solaris Production Release) 1.6.0_18
Sun JRE (Solaris Production Release) 1.6.0_15
Sun JRE (Solaris Production Release) 1.6.0_14
Sun JRE (Solaris Production Release) 1.6.0_11
Sun JRE (Solaris Production Release) 1.6.0_03
Sun JRE (Solaris Production Release) 1.6.0_02
Sun JRE (Solaris Production Release) 1.6.0_01
Sun JRE (Linux Production Release) 1.6 _17
Sun JRE (Linux Production Release) 1.6 _13
Sun JRE (Linux Production Release) 1.6 _12
Sun JRE (Linux Production Release) 1.6 _10
Sun JRE (Linux Production Release) 1.6 _07
Sun JRE (Linux Production Release) 1.6 _06
Sun JRE (Linux Production Release) 1.6 _05
Sun JRE (Linux Production Release) 1.6 _04
Sun JRE (Linux Production Release) 1.6
Sun JRE (Linux Production Release) 1.7.0_2
Sun JRE (Linux Production Release) 1.7
Sun JRE (Linux Production Release) 1.6.0_30
Sun JRE (Linux Production Release) 1.6.0_28
Sun JRE (Linux Production Release) 1.6.0_27
Sun JRE (Linux Production Release) 1.6.0_26
Sun JRE (Linux Production Release) 1.6.0_25
Sun JRE (Linux Production Release) 1.6.0_24
Sun JRE (Linux Production Release) 1.6.0_23
Sun JRE (Linux Production Release) 1.6.0_22
Sun JRE (Linux Production Release) 1.6.0_21
Sun JRE (Linux Production Release) 1.6.0_20
Sun JRE (Linux Production Release) 1.6.0_19
Sun JRE (Linux Production Release) 1.6.0_18
Sun JRE (Linux Production Release) 1.6.0_15
Sun JRE (Linux Production Release) 1.6.0_14
Sun JRE (Linux Production Release) 1.6.0_11
Sun JRE (Linux Production Release) 1.6.0_03
Sun JRE (Linux Production Release) 1.6.0_02
Sun JRE (Linux Production Release) 1.6.0_01
Sun JDK (Windows Production Release) 1.7
Sun JDK (Windows Production Release) 1.6 _17
Sun JDK (Windows Production Release) 1.6 _14
Sun JDK (Windows Production Release) 1.6 _13
Sun JDK (Windows Production Release) 1.6 _11
Sun JDK (Windows Production Release) 1.6 _10
Sun JDK (Windows Production Release) 1.6 _07
Sun JDK (Windows Production Release) 1.6 _06
Sun JDK (Windows Production Release) 1.6 _05
Sun JDK (Windows Production Release) 1.6 _04
Sun JDK (Windows Production Release) 1.6
Sun JDK (Windows Production Release) 1.7.0_2
Sun JDK (Windows Production Release) 1.6.0_30
Sun JDK (Windows Production Release) 1.6.0_28
Sun JDK (Windows Production Release) 1.6.0_27
Sun JDK (Windows Production Release) 1.6.0_26
Sun JDK (Windows Production Release) 1.6.0_25
Sun JDK (Windows Production Release) 1.6.0_24
Sun JDK (Windows Production Release) 1.6.0_23
Sun JDK (Windows Production Release) 1.6.0_22
Sun JDK (Windows Production Release) 1.6.0_21
Sun JDK (Windows Production Release) 1.6.0_20
Sun JDK (Windows Production Release) 1.6.0_19
Sun JDK (Windows Production Release) 1.6.0_18
Sun JDK (Windows Production Release) 1.6.0_15
Sun JDK (Windows Production Release) 1.6.0_03
Sun JDK (Windows Production Release) 1.6.0_02
Sun JDK (Windows Production Release) 1.6.0_01-b06
Sun JDK (Windows Production Release) 1.6.0_01
Sun JDK (Solaris Production Release) 1.7
Sun JDK (Solaris Production Release) 1.6 _17
Sun JDK (Solaris Production Release) 1.6 _14
Sun JDK (Solaris Production Release) 1.6 _13
Sun JDK (Solaris Production Release) 1.6 _11
Sun JDK (Solaris Production Release) 1.6 _10
Sun JDK (Solaris Production Release) 1.6 _07
Sun JDK (Solaris Production Release) 1.6 _06
Sun JDK (Solaris Production Release) 1.6 _05
Sun JDK (Solaris Production Release) 1.6 _04
Sun JDK (Solaris Production Release) 1.6 _01-b06
Sun JDK (Solaris Production Release) 1.6
Sun JDK (Solaris Production Release) 1.7.0_2
Sun JDK (Solaris Production Release) 1.6.0_30
Sun JDK (Solaris Production Release) 1.6.0_28
Sun JDK (Solaris Production Release) 1.6.0_27
Sun JDK (Solaris Production Release) 1.6.0_26
Sun JDK (Solaris Production Release) 1.6.0_25
Sun JDK (Solaris Production Release) 1.6.0_24
Sun JDK (Solaris Production Release) 1.6.0_23
Sun JDK (Solaris Production Release) 1.6.0_22
Sun JDK (Solaris Production Release) 1.6.0_21
Sun JDK (Solaris Production Release) 1.6.0_20
Sun JDK (Solaris Production Release) 1.6.0_19
Sun JDK (Solaris Production Release) 1.6.0_18
Sun JDK (Solaris Production Release) 1.6.0_15
Sun JDK (Solaris Production Release) 1.6.0_03
Sun JDK (Solaris Production Release) 1.6.0_02
Sun JDK (Solaris Production Release) 1.6.0_01
Sun JDK (Linux Production Release) 1.7
Sun JDK (Linux Production Release) 1.6 _17
Sun JDK (Linux Production Release) 1.6 _14
Sun JDK (Linux Production Release) 1.6 _13
Sun JDK (Linux Production Release) 1.6 _11
Sun JDK (Linux Production Release) 1.6 _10
Sun JDK (Linux Production Release) 1.6 _07
Sun JDK (Linux Production Release) 1.6 _06
Sun JDK (Linux Production Release) 1.6 _05
Sun JDK (Linux Production Release) 1.6 _04
Sun JDK (Linux Production Release) 1.6 _01-b06
Sun JDK (Linux Production Release) 1.6 _01
Sun JDK (Linux Production Release) 1.6
Sun JDK (Linux Production Release) 1.7.0_2
Sun JDK (Linux Production Release) 1.6.0_30
Sun JDK (Linux Production Release) 1.6.0_28
Sun JDK (Linux Production Release) 1.6.0_27
Sun JDK (Linux Production Release) 1.6.0_26
Sun JDK (Linux Production Release) 1.6.0_25
Sun JDK (Linux Production Release) 1.6.0_24
Sun JDK (Linux Production Release) 1.6.0_23
Sun JDK (Linux Production Release) 1.6.0_22
Sun JDK (Linux Production Release) 1.6.0_21
Sun JDK (Linux Production Release) 1.6.0_20
Sun JDK (Linux Production Release) 1.6.0_19
Sun JDK (Linux Production Release) 1.6.0_18
Sun JDK (Linux Production Release) 1.6.0_15
Sun JDK (Linux Production Release) 1.6.0_03
Sun JDK (Linux Production Release) 1.6.0_02
Sun JDK (Linux Production Release) 1.6.0 Update 7
Sun JDK (Linux Production Release) 1.6.0 Update 6
Sun JDK (Linux Production Release) 1.6.0 Update 5
Sun JDK (Linux Production Release) 1.6.0 Update 4
Sun JDK (Linux Production Release) 1.6.0 Update 3
Sun JDK (Linux Production Release) 1.6.0 Update 21
Sun JDK (Linux Production Release) 1.6.0 Update 20
Sun JDK (Linux Production Release) 1.6.0 Update 19
Sun JDK (Linux Production Release) 1.6.0 Update 18
Sun JDK (Linux Production Release) 1.6.0 Update 17
Sun JDK (Linux Production Release) 1.6.0 Update 16
Sun JDK (Linux Production Release) 1.6.0 Update 15
Sun JDK (Linux Production Release) 1.6.0 Update 14
Sun JDK (Linux Production Release) 1.6.0 Update 13
Sun JDK (Linux Production Release) 1.6.0 Update 12
Sun JDK (Linux Production Release) 1.6.0 Update 11
Sun JDK (Linux Production Release) 1.6.0 Update 10
Sun Java System Web Server 6.1
Sun Java System Application Server 8.2
Sun Java System Application Server 8.1
Sun iPlanet Web Server 7.0
Red Hat Enterprise Linux Workstation Optional 6
Red Hat Enterprise Linux Workstation 6
Red Hat Enterprise Linux Server Optional 6
Red Hat Enterprise Linux Server 6
Red Hat Enterprise Linux HPC Node Optional 6
Red Hat Enterprise Linux HPC Node 6
Red Hat Enterprise Linux Desktop Optional 6
Red Hat Enterprise Linux Desktop 6
Oracle Weblogic Server 10.3.3
Oracle Weblogic Server 9.2.4
Oracle Weblogic Server 10.3.5.0
Oracle Weblogic Server 10.3.4
Oracle Glassfish Server 3.1.1
Oracle Glassfish Server 3.1
Oracle Glassfish Server 3.0.1
Oracle Glassfish Server 3.0
Oracle Glassfish Server 2.1.1
Oracle Glassfish Server 2.1
Oracle Glassfish Server 2.0
Oracle Glassfish Server 1.0 Ur1 Po1
Oracle Glassfish Server 1.0 Ur1
Oracle Glassfish Server 1.0
Oracle Communications Server 2.0
Oracle Application Server 10g 10.1.3 .5.0 R3
Not Vulnerable:

Security Discussion

Oracle GlassFish Server is prone to a denial-of-service vulnerability.

An attacker can exploit this issue by sending specially crafted forms in HTTP POST requests.

Oracle GlassFish Server 3.1.1 and prior versions are vulnerable.

Proof of Concept and Security Exploits

An attacker can use readily available tools to exploit this issue.

Security Solution(s)

Solution:
Vendor updates are available. Please see the references for more information.

Security References(s)

References:

Contact Us

Security Penetration Testing

Security Questions

Security Dashboard

Emagined Security Blog featuring Dr. Eugene Schultz
Site Updated June 19, 2013
©2000-2013 Emagined Security
All Rights Reserved

Secure Web Programming
by Vizual Services