Impact
The vulnerability allows an authenticated attacker to exceed the session flow control incoming window in Apache Qpid ProtonJ2, leading to resource exhaustion and denial of service. It is classified as a Capacity Overflow (CWE-770).
Affected Systems
Systems running Apache Qpid ProtonJ2 up to and including version 1.1.0 are impacted. The product is maintained by the Apache Software Foundation and it is inferred that any Java application embedding ProtonJ2 may be affected.
Risk and Exploitability
Because authentication is required, the likely attack vector involves an authenticated network channel or local access with valid credentials. No CVSS score or EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog. Applying the upgrade to 1.2.0 removes the risk.
OpenCVE Enrichment