Impact
A small WS‑Policy document that includes repeated policy references can trigger Neethi to expand the same references exponentially during the normalization phase, consuming excessive CPU and memory. This uncontrolled resource consumption can exhaust the host system’s resources, causing the Neethi component—and potentially the enclosing application—to become unresponsive. The vulnerability is a classic resource exhaustion flaw that can interrupt service availability.
Affected Systems
Apache Neethi, the policy toolkit used in Apache Axis2 and other Java‑based web service stacks, is impacted. All releases older than version 3.2.4 are affected, as that release introduces the fix. Therefore any deployment that processes WS‑Policy documents without filtering or limiting reference complexity is potentially vulnerable.
Risk and Exploitability
The CVSS score is not reported in the available data, and the EPSS metric is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed to date. However, the flaw can be triggered remotely by sending a crafted WS‑Policy document to any service that employs Neethi for policy normalization. No special privileges are required, and the attack can be performed over the standard web service interface.
OpenCVE Enrichment