CyberRota Analysis
AI-GeneratedThe vulnerability allows a crafted WS-Policy document to cause Neethi to exponentially re-expand repeated policy references, leading to significant CPU and memory consumption that results in a denial of service. Organizations utilizing Neethi for policy management should prioritize this issue to prevent potential service disruptions. It is recommended to upgrade to version 3.2.4 to mitigate this risk.
Original NVD Description
A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)