Impact
Apache Neethi contains a flaw that permits an attacker to supply specially crafted policies which bypass the global alternative-output budgeting that protects against excessive policy alternatives. When the budget check is circumvented, the policy engine attempts to generate a large number of normalized policy alternatives, consuming significant CPU and memory. The result is a denial of service that can degrade application availability and overall system performance.
Affected Systems
All installations of Apache Neethi running version 3.2.2 or earlier are affected. The issue was resolved in the 3.2.3 release, which reinstates the budgeting safeguard.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact. The EPSS score of less than 1% suggests a very low probability of observed exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves supplying crafted policies, implying that an attacker must have the ability to influence policy definitions. If an application accepts dynamic policy input from untrusted sources, the risk increases, but without such access the exploitation path is limited.
OpenCVE Enrichment