
Проблема в Silverpeas v.6.4.2 и более ранних версиях позволяет удалённому злоумышленнику вызвать отказ в обслуживании через функцию смены пароля.
An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.
If the password change request is intercepted and a sufficiently long(1MB) string is supplied as the password to use, system resources will be overwhelmed by the attempt to hash the password and cause a DoS.