GlassFish: hash table collisions CPU usage DoS (oCERT-2011-003)
Published Dec 30, 2011
5.0
MEDIUMCVSS 2.0
EPSS 67.93%
Description
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka Oracle security ticket S0104869.
Affected products
No data.
- ≤ 3.1.1
- 2.1.1
- 3.0.1
No data.
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.25.1.10.6.el5_8
Fixed · RHSA-2012:0322
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.0-1.43.1.10.6.el6_2
Fixed · RHSA-2012:0135
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9
Fixed · RHSA-2013:1455
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.10.1-1jpp.1.el5
Fixed · RHSA-2012:0514
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.31-1jpp.1.el5
Fixed · RHSA-2012:0139
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-ibm-1:1.6.0.10.1-1jpp.5.el6_2
Fixed · RHSA-2012:0514
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.31-1jpp.1.el6_2
Fixed · RHSA-2012:0139
Red Hat JBoss BRMS 5
security
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.25.1.10.6.el5_8 | Fixed | RHSA-2012:0322 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.0-1.43.1.10.6.el6_2 | Fixed | RHSA-2012:0135 |
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9 | Fixed | RHSA-2013:1455 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.10.1-1jpp.1.el5 | Fixed | RHSA-2012:0514 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.31-1jpp.1.el5 | Fixed | RHSA-2012:0139 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-ibm-1:1.6.0.10.1-1jpp.5.el6_2 | Fixed | RHSA-2012:0514 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.31-1jpp.1.el6_2 | Fixed | RHSA-2012:0139 |
| Red Hat JBoss BRMS 5 | security | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue affects the GlassFish Web Container component. This component is not shipped with any Red Hat products. JBoss Web and Tomcat provide the web container used in all JBoss products.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 67.93% (0.67932) | 99.30th | v5 (v2026.06.15) |
| Jun 15, 2026 | 68.91% (0.68914) | 99.26th | v5 (v2026.06.15) |
| Feb 3, 2026 | 58.63% (0.58626) | 98.16th | v4 (v2025.03.14) |
| Dec 28, 2025 | 55.57% (0.55569) | 97.97th | v4 (v2025.03.14) |
| Dec 27, 2025 | 57.07% (0.57072) | 98.04th | v4 (v2025.03.14) |
| Nov 20, 2025 | 55.57% (0.55569) | 97.99th | v4 (v2025.03.14) |
| Oct 28, 2025 | 52.41% (0.52412) | 97.77th | v4 (v2025.03.14) |
| Oct 27, 2025 | 53.96% (0.53960) | 97.87th | v4 (v2025.03.14) |
| Oct 1, 2025 | 52.41% (0.52412) | 97.85th | v4 (v2025.03.14) |
| Jul 30, 2025 | 53.96% (0.53960) | 97.89th | v4 (v2025.03.14) |
| Mar 30, 2025 | 52.41% (0.52412) | 97.71th | v4 (v2025.03.14) |
| Mar 29, 2025 | 62.28% (0.62283) | 97.66th | v4 (v2025.03.14) |
| Mar 19, 2025 | 52.41% (0.52412) | 97.62th | v4 (v2025.03.14) |
| Mar 17, 2025 | 50.62% (0.50620) | 97.58th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.65% (0.02647) | 90.76th | v3 (v2023.03.01) |
| Jan 17, 2024 | 2.52% (0.02522) | 89.07th | v3 (v2023.03.01) |
| Nov 24, 2023 | 3.39% (0.03392) | 90.40th | v3 (v2023.03.01) |
| Sep 27, 2023 | 4.73% (0.04727) | 91.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.93% (0.03927) | 90.61th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (29)
- http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html mailing-listx_refsource_BUGTRAQ
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00010.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=133364885411663&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=133847939902305&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=134254957702612&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=139344343412337&w=2 vendor-advisoryx_refsource_HP
- http://rhn.redhat.com/errata/RHSA-2012-0514.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1455.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/48073 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48074 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48589 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48950 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/57126 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2012/dsa-2420 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/903934 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 vendor-advisoryx_refsource_MANDRIVA
- http://www.nruns.com/_downloads/advisory28122011.pdf x_refsource_MISC
- http://www.ocert.org/advisories/ocert-2011-003.html x_refsource_MISC
- http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2011-5035 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=771283 Issue Tracking
- https://github.com/FireFart/HashCollision-DOS-POC/blob/master/HashtablePOC.py x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2011-5035
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16908 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2011-5035
Change history (0)
No recorded changes yet.