CVE-2011-5035 describes a denial-of-service vulnerability in Oracle Glassfish versions 2.1.1, 3.0.1, and 3.1.1, as well as related Oracle products like Communications Server and Sun Java System Application Server. The flaw allows remote attackers to consume excessive CPU resources by sending specially crafted form parameters that trigger predictable hash collisions. With a CVSS score of 5.0 (medium severity), this vulnerability is easily exploitable over the network with low attack complexity, leading to a denial of service without requiring authentication. While not listed in CISA's KEV catalog, a Metasploit module exists for hash table collisions, and it has garnered some community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:glassfish_server:*:*:*:*:*:*:*:* | ||
2.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:glassfish_server:2.1.1:*:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:glassfish_server:3.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.