Jboss EAP Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability - CVE-2011-4610
JBoss Web as used in Red Hat JBoss Communications Platform before 5.1.3 Enterprise Web Platform before 5.1.2 Enterprise Application Platform before 5.1.2 and other products allows remote attackers to cause a denial of service (infinite loop) via vectors related to a crafted UTF-8 and a quotsurrogate pair characterquot that is quotat the boundary of an internal buffer.quot