Denial of Service in OpenDaylight odl-mdsal-xsql feature. Java out of memory error and significant increase in resource consumption. From thesis: https://aaltodoc.aalto.fi/bitstream/handle/123456789/21584/master_Bidaj_Andi_2016.pdf?sequence=1 Vulnerability 3: Odl-mdsal-xsql component exposes two ports for users to query or update database tables using XSQL, an XML-based query language. If a crafted fuzzing string is sent multiple times to ports 40004 and 34343, a DoS can be caused.
Created opendaylight tracking bugs for this issue: Affects: openstack-rdo [bug 1447866]
Acknowledgments: Name: OpenDaylight project Upstream: Andi Bidaj