Impact
Apache Answer versions up to 2.0.1 exhibit an improper handling of a length parameter inconsistency in the parsing of the Accept‑Language header. An attacker who can send a crafted header can cause the server to consume excessive CPU resources while parsing, degrading service availability.
Affected Systems
The vulnerability affects Apache Answer through version 2.0.1. The affected vendor is Apache Software Foundation and the product is Apache Answer. Version 2.0.2 and later contain a fix.
Risk and Exploitability
The vulnerability can be triggered by unauthenticated attackers. The CVSS score is 7.5, classifying it as high severity. The EPSS score is 0.00181, indicating a very low but non‑zero probability of exploitation. The denial‑of‑service impact coupled with the easy remote trigger suggests an urgent remedial action.
OpenCVE Enrichment