CVE-2011-4610
Last modified
CVE-2011-4610 is a vulnerability of currently unknown severity. JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer.". EPSS estimates a 2.17% chance of exploitation in the next 30 days.
Description
JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Communications Platform | <= 5.1 |
| Redhat | Jboss Enterprise Application Platform | <= 5.1.2 |
| Redhat | Jboss Enterprise Brms Platform | <= 5.1.0 |
| Redhat | Jboss Enterprise Web Platform | <= 5.1.2 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=767871Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=767871Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4610?
How severe is CVE-2011-4610?
How do I fix CVE-2011-4610?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4604The bat_socket_read function in net/batman-adv/icmp_socket.c…
- CVE-2011-4605The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFac…
- CVE-2011-4606Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) …
- CVE-2011-4607PuTTY 0.59 through 0.61 does not clear sensitive process mem…
- CVE-2011-4608mod_cluster in JBoss Enterprise Application Platform 5.1.2 f…
- CVE-2011-4609The svc_run function in the RPC implementation in glibc befo…
- CVE-2011-4611Integer overflow in the perf_event_interrupt function in arc…
- CVE-2011-4612icecast before 2.3.3 allows remote attackers to inject contr…
- CVE-2011-4613The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux …
- CVE-2011-4614PHP remote file inclusion vulnerability in Classes/Controlle…
- CVE-2011-4615Multiple cross-site scripting (XSS) vulnerabilities in Zabbi…
- CVE-2011-4616Cross-site scripting (XSS) vulnerability in the HTML-Templat…
Are you affected by CVE-2011-4610?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
