vulnerability

Red Hat JBoss EAP: CVE-2016-3110: Improper Input Validation

Severity
5
CVSS
(AV:L/AC:M/Au:N/C:N/I:N/A:C)
Published
Aug 22, 2016
Added
Sep 19, 2024
Modified
Jul 2, 2025

Description

mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.. It was discovered that it is possible to remotely Segfault Apache http server with a specially crafted string sent to the mod_cluster via service messages (MCMP).

Solution

red-hat-jboss-eap-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.