Resource exhaustion in Jetty - CVE-2021-28165
Published: April 1, 2021 / Updated: November 22, 2023
Jetty
IBM Business Automation Workflow
IBM Process Mining
Crowd Data Center
Jira Software Data Center
IBM Customer and Network Analytics for Communications Service Providers and Datasets
IBM Integration Bus
Netcool Operations Insight
Red Hat Integration Camel-K
IBM MaaS360 Mobile Enterprise Gateway
Datastax Enterprise with IBM
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
Dell NetWorker Virtual Edition
Security Directory Integrator
Cloudera Observability with IBM
Rational Performance Tester
IBM Security Verify Directory
IBM Enterprise Records
Engineering Lifecycle Management - Jazz Foundation
IBM Security Directory Suite
Dell Security Management Server
Red Hat Developer Tools
IBM App Connect Enterprise
Oracle REST Data Services
Sterling Connect:Direct Browser User Interface
Rational Change
Oracle Unified Directory
AMQ Streams
Jenkins LTS
Jenkins
Oracle Communications Converged Application Server
AMQ Broker
Oracle Communications Cloud Native Core Policy
IBM Analytic Accelerator Framework for Communication Service Providers
Red Hat OpenShift Container Platform
Traffix SDC
Oracle Autovue for Agile Product Lifecycle Management
Crowd Server
IBM Qradar SIEM
Jira Software Server
IBM Cognos Command Center
Zimbra Collaboration
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Siebel CRM End User
runc (Red Hat package)
cri-tools (Red Hat package)
cri-o (Red Hat package)
ignition (Red Hat package)
jenkins (Red Hat package)
openshift-ansible (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
jetty-start
jetty-unixsocket
jetty-server
jetty-jmx
jetty-cdi
jetty-proxy
jetty-http2-common
jetty-webapp
jetty-websocket-common
jetty-osgi-boot-warurl
jetty-jstl
jetty-util-ajax
jetty-http
jetty-websocket-server
jetty-jspc-maven-plugin
jetty-http2-hpack
jetty-annotations
jetty-jsp
jetty-alpn-client
jetty-client
jetty-http2-server
jetty-jaspi
jetty-quickstart
jetty-alpn-server
jetty-security
jetty-io
jetty-osgi-alpn
jetty-http2-http-client-transport
jetty-fcgi-server
jetty-infinispan
jetty-continuation
jetty-osgi-boot-jsp
jetty-osgi-boot
jetty-maven-plugin
jetty-websocket-client
jetty-xml
jetty-javax-websocket-client-impl
jetty-javadoc
jetty-jaas
jetty-websocket-servlet
jetty-http-spi
jetty
jetty-util
jetty-rewrite
jetty-websocket-api
jetty-fcgi-client
jetty-plus
jetty-httpservice
jetty-deploy
jetty-servlet
jetty-spring
jetty-javax-websocket-server-impl
jetty-servlets
jetty-jndi
jetty-http2-client
jetty-project
jetty-nosql
jetty-ant
rh-eclipse-jetty (Red Hat package)
openstack-ironic (Red Hat package)
watsonx.data
Dell EMC Storage Monitoring and Reporting (SMR)
IBM Storage Scale System
IBM InfoSphere Information Server
Vue PACS
Contrail Networking
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing large TLS frames. A remote attacker can send specially crafted data to the server, trigger CPU high load and perform a denial of service (DoS) attack.