Oracle TimesTen In-Memory Database HTTP Request Denial of Service
| TSL ID | FSC20100201-03 |
| CVE ID(s) | Not available. |
| Severity | High |
| Description | A denial of service vulnerability has been reported in Oracle TimesTen In-Memory Database service. The vulnerability is due to an input validation error while parsing specially crafted HTTP GET requests. Remote unauthenticated attackers can exploit this vulnerability by sending an overly large HTTP request to the 'timestend' daemon running on port 17000/TCP. Successful exploitation would cause the database service to terminate abnormally, resulting in the Denial of Service condition. A patch or new revision is not available as of now. As a workaround, allow only trusted users to access the affected service. |
| Affected Products |
|
| CVSS Score |
Base 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C):
|