Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2021-28165 Details
Description
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 27, 2025Exploitation: NoneAutomatable: YesTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-551 | Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | [email protected] |
| CWE-755 | Improper Handling of Exceptional Conditions | CISA-ADP |
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse jetty | >= 7.2.2, < 9.4.39 >= 10.0.0, < 10.0.2 >= 11.0.0, < 11.0.2 |
CPE
Remediation
| |
| oracle autovue for agile product lifecycle management | 21.0.2 |
CPE
Remediation
| |
| oracle communications cloud native core policy | 1.14.0 |
CPE
Remediation
| |
| oracle communications element manager | 8.2.2 |
CPE
Remediation
| |
| oracle communications services gatekeeper | 7.0 |
CPE
Remediation
| |
| oracle communications session report manager | >= 8.0.0.0, <= 8.2.4.0 |
CPE
Remediation
| |
| oracle communications session route manager | >= 8.0.0.0, <= 8.2.4.0 |
CPE
Remediation
| |
| oracle rest data services | < 21.3 |
CPE
Remediation
| |
| oracle siebel core - automation | <= 21.9 |
CPE
Remediation
| |
| jenkins jenkins | < 2.277.3 < 2.286 |
CPE
Remediation
| |
| netapp cloud manager | < 3.9.8 |
CPE
Remediation
| |
| netapp e-series performance analyzer | < 3.0 |
CPE
Remediation
| |
| netapp e-series santricity os controller | >= 11.0.0, < 11.70.1 |
CPE
Remediation
| |
| netapp e-series santricity storage | < 1.10 |
CPE
Remediation
| |
| netapp e-series santricity web services | < 5.1 |
CPE
Remediation
| |
| netapp ontap tools | < 9.10 |
CPE
Remediation
| |
| netapp santricity cloud connector | All versions |
CPE
Remediation
| |
| netapp santricity web services proxy | < 5.1 |
CPE
Remediation
| |
| netapp snapcenter | < 4.6 |
CPE
Remediation
| |
| netapp storage replication adapter for clustered data ontap | < 9.10 |
CPE
Remediation
| |
| netapp vasa provider for clustered data ontap | < 9.10 |
CPE
Remediation
| |
Change History
50 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 27, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jul 29, 2022 | Reanalysis | [email protected] |
| May 12, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Apr 13, 2022 | Reanalysis | [email protected] |
| Apr 12, 2022 | Modified Analysis | [email protected] |
| Feb 7, 2022 | CVE Modified | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Aug 13, 2021 | CVE Modified | [email protected] |
| Aug 6, 2021 | CVE Modified | [email protected] |
| Jul 20, 2021 | CVE Modified | [email protected] |
| Jul 15, 2021 | CVE Modified | [email protected] |
| Jul 11, 2021 | CVE Modified | [email protected] |
| Jun 23, 2021 | CVE Modified | [email protected] |
| Jun 11, 2021 | CVE Modified | [email protected] |
| May 17, 2021 | CVE Modified | [email protected] |
| May 7, 2021 | CVE Modified | [email protected] |
| Apr 26, 2021 | CVE Modified | [email protected] |
| Apr 26, 2021 | CVE Modified | [email protected] |
| Apr 20, 2021 | CVE Modified | [email protected] |
| Apr 14, 2021 | CVE Modified | [email protected] |
| Apr 13, 2021 | CVE Modified | [email protected] |
| Apr 13, 2021 | CVE Modified | [email protected] |
| Apr 13, 2021 | CVE Modified | [email protected] |
| Apr 13, 2021 | CVE Modified | [email protected] |
| Apr 12, 2021 | CVE Modified | [email protected] |
| Apr 12, 2021 | CVE Modified | [email protected] |
| Apr 12, 2021 | CVE Modified | [email protected] |
| Apr 12, 2021 | CVE Modified | [email protected] |
| Apr 10, 2021 | CVE Modified | [email protected] |
| Apr 10, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 8, 2021 | CVE Modified | [email protected] |
| Apr 7, 2021 | CVE Modified | [email protected] |
| Apr 7, 2021 | CVE Modified | [email protected] |
| Apr 7, 2021 | CVE Modified | [email protected] |
| Apr 6, 2021 | Initial Analysis | [email protected] |