← Vulnerability feed

Vulnerability record · CVE-2011-4461 · published 30 December 2011

CVE-2011-4461: Oracle sun storage common array manager vulnerability

Oracle · Sun Storage Common Array Manager

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

5.3 CVSS 3.0 Medium EPSS 4.9% · top 8.2% CWE-310 · CWE-310
5.3CVSS 3.0 base score, v2 5.0
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html
http://marc.info/?l=bugtraq&m=143387688830075&w=2
http://secunia.com/advisories/47408
http://secunia.com/advisories/48981
http://www.kb.cert.org/vuls/id/903934 US Government Resource
http://www.nruns.com/_downloads/advisory28122011.pdf
http://www.ocert.org/advisories/ocert-2011-003.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.securitytracker.com/id?1026475
http://www.ubuntu.com/usn/USN-1429-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/72017
https://security.netapp.com/advisory/ntap-20190307-0004/
http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html
http://marc.info/?l=bugtraq&m=143387688830075&w=2
http://secunia.com/advisories/47408
http://secunia.com/advisories/48981
http://www.kb.cert.org/vuls/id/903934 US Government Resource
http://www.nruns.com/_downloads/advisory28122011.pdf
http://www.ocert.org/advisories/ocert-2011-003.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.securitytracker.com/id?1026475
http://www.ubuntu.com/usn/USN-1429-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/72017
https://security.netapp.com/advisory/ntap-20190307-0004/

Track CVE-2011-4461 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2009-4611Mortbay jetty improper input validation vulnerabilityMort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to …EPSS 3.2%6.1CVE-2009-5048Mortbay jetty cross-site scripting vulnerabilityCookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.EPSS 1.6%6.1CVE-2009-5049Mortbay jetty cross-site scripting vulnerabilityWebApp JSP Snoop page XSS in jetty though 6.1.21.EPSS 1.6%5.0CVE-2009-4609Mortbay jetty information exposure vulnerabilityThe Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via …EPSS 1.8%5.0CVE-2009-1523Mortbay jetty path traversal vulnerabilityDirectory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to…EPSS 26%5.0CVE-2005-3747Mortbay jetty information exposure vulnerabilityUnspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp file…EPSS 4.4%4.3CVE-2009-4610Mortbay jetty cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via…EPSS 3.0%4.3CVE-2009-4612Mortbay jetty cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inj…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2011-4461), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.