Impact
An authenticated attacker can send data that exceeds the broker’s incoming session flow control window, which may cause the Qpid Broker‑J server to become unresponsive or crash. The weakness is identified as a Resource Exhaustion flaw (CWE‑770) and can compromise availability for affected services.
Affected Systems
The bug affects Apache Qpid Broker‑J versions up to and including 10.0.1, as released by the Apache Software Foundation.
Risk and Exploitability
The vulnerability requires the user to be authenticated before exploitation can occur; an authenticated attacker can send traffic that exceeds the broker’s session flow‑control window, potentially leading to a denial of service. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the overall risk to a given environment depends on factors such as how exposed the broker is and how many authenticated users are present, but the severity alone does not quantify exploitation likelihood.
OpenCVE Enrichment