Red Hat Bugzilla – Bug 1095974
CVE-2014-0219 Karaf: denial of service via shutdown port
Last modified: 2018-05-10 14:12:04 EDT
It was found that Apache Karaf enables a shutdown port, which could be used by a local attacker to shutdown the Karaf server. By default, the shutdown port is bound to a random high port, listening only on the loopback interface. A local attacker could send the shutdown command to all listening high ports, and shutdown the Karaf server.
Acknowledgements: This issue was discovered by David Jorm of Red Hat Product Security.