CVE-2014-1972 is a vulnerability in Apache Tapestry
Published on August 22, 2015
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consumption) or execute arbitrary code via crafted serialized data.
Products Associated with CVE-2014-1972
Want to know whenever a new CVE is published for Apache Tapestry? stack.watch will email you.
Exploit Probability
EPSS
9.60%
Percentile
95.10%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.