Impact
A specially crafted pair of WS‑Policy documents can force Apache Neethi’s policy‑intersection routine to perform exponential amounts of work, tying up the CPU for extended periods. The flaw is an uncontrolled resource‑consumption vulnerability (CWE‑400) that results in a denial‑of‑service condition, blocking legitimate traffic and exhausting system resources.
Affected Systems
The vulnerability resides in Apache Neethi libraries prior to version 3.2.4. Any application or service that imports or processes WS‑Policy documents using an unpatched Neethi package is affected, whether it is a client or server component.
Risk and Exploitability
Because the flaw can be triggered remotely by sending crafted policy documents and does not require authentication, an attacker can invoke it from any network location that can reach the policy‑processing endpoint. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. With no CVSS score provided, the potential for high CPU usage and availability impact suggests a significant risk that warrants patching before widespread exploitation.
OpenCVE Enrichment