CVE-2011-5034

Apache Geronimo < 2.2.1 - Improper Input Validation

Title source: rule

Description

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.

Exploits (1)

exploitdb WORKING POC
phpwebappsphp
https://www.exploit-db.com/exploits/2012

References (17)

Scores

EPSS 0.7334
EPSS Percentile 98.8%

Details

CWE
CWE-20
Status published
Products (18)
apache/geronimo 1.0
apache/geronimo 1.1
apache/geronimo 1.1.1
apache/geronimo 1.2
apache/geronimo 2.0.1
apache/geronimo 2.0.2
apache/geronimo 2.1
apache/geronimo 2.1.1
apache/geronimo 2.1.2
apache/geronimo 2.1.3
... and 8 more
Published Dec 30, 2011
Tracked Since Feb 18, 2026