Impact
A flaw in Apache Neethi allows an attacker to manually trigger the retrieval of a remote policy reference via the API. Based on the description, it is inferred that when a very large policy is fetched, the library consumes excessive resources during the download, which can exhaust server memory or CPU and cause a denial of service. The weakness is a resource exhaustion vulnerability.
Affected Systems
The issue affects Apache Neethi, a subproject of the Apache Software Foundation. Users using versions prior to 3.2.3 are vulnerable. The vendor recommends upgrading to version 3.2.3, which introduces a default maximum size for data read from remote policy references.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity. The EPSS score is less than 1%, implying that the probability of exploitation is low but not negligible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires the ability to invoke the API that fetches remote policy references, which is likely performed remotely by an attacker with network access to the API endpoint.
OpenCVE Enrichment