Vulnerabilities > CVE-2015-8786 - Resource Management Errors vulnerability in multiple products

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
oracle
pivotal-software
CWE-399

Summary

The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.

Vulnerable Configurations

Part Description Count
OS
Oracle
1
Application
Pivotal_Software
1

Common Weakness Enumeration (CWE)

Redhat

advisories
  • rhsa
    idRHSA-2017:0226
  • rhsa
    idRHSA-2017:0530
  • rhsa
    idRHSA-2017:0531
  • rhsa
    idRHSA-2017:0532
  • rhsa
    idRHSA-2017:0533
rpms
  • rabbitmq-server-0:3.3.5-30.el7ost
  • rabbitmq-server-0:3.3.5-31.el7ost
  • rabbitmq-server-0:3.3.5-31.el7ost
  • rabbitmq-server-0:3.3.5-31.el7ost
  • rabbitmq-server-0:3.1.5-7.el6ost