JBoss Web, as used in Red Hat JBoss Communications Platform before 5.1.3, Enterprise Web Platform before 5.1.2, Enterprise Application Platform before 5.1.2, and other products, allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a "surrogate pair character" that is "at the boundary of an internal buffer."
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss_enterprise_application_platform | - | 5.1.2.x |
| redhat / jboss_enterprise_brms_platform | - | 5.1.0.x |
| redhat / jboss_communications_platform | - | 5.1.x |
| redhat / jboss_enterprise_web_platform | - | 5.1.2.x |