Vulnerabilities > CVE-2014-1972 - Resource Management Errors vulnerability in Apache Tapestry

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.

Vulnerable Configurations

Part Description Count
Application
Apache
139

Common Weakness Enumeration (CWE)