Impact
Apache MyFaces may process request parameters without bounding, letting a remote attacker supply crafted inputs that consume excessive server resources. This uncontrolled resource consumption can push the application into a denial of service state. The weakness is a classic case of CWE-400, where input validation fails to limit resource usage.
Affected Systems
The vulnerability affects Apache MyFaces releases older than 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, and 4.1.4, as well as any unsupported older versions. These are deployments that were built with the Apache Software Foundation’s MyFaces framework and have not applied the patch that restricts request size.
Risk and Exploitability
With a CVSS score of 7.5, the flaw carries a high severity rating, yet its EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. While no authentication is required, the attack vector is inferred to be remote, exploiting the web application’s ability to parse incoming HTTP requests. A successful exploit would exhaust critical application resources, resulting in a denial of service for legitimate users.
OpenCVE Enrichment