CVE-2016-5004

MEDIUM

Apache Ws-xmlrpc - Denial of Service

Title source: rule

Description

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.

Scores

CVSS v3 6.5
EPSS 0.0114
EPSS Percentile 78.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (3)
apache/ws-xmlrpc
org.apache.xmlrpc/xmlrpc-common Maven
n/a/n/a
Published Jun 06, 2017
Tracked Since Feb 18, 2026