Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2160

Опубликовано: 26 июн. 2013
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 6jbossws-cxfNot affected
Red Hat JBoss Enterprise Web Server 1fuse-6Affected
Red Hat JBoss Enterprise Web Server 1fuse-enterprise-esb-7Affected
Fuse ESB Enterprise 7.1.0FixedRHSA-2013:102809.07.2013
Red Hat JBoss Fuse 6.0FixedRHSA-2013:118529.08.2013
Red Hat JBoss Portal Platform 6.1cxfFixedRHSA-2013:143716.10.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=929197apache-cxf: Multiple denial of service flaws in the StAX parser

EPSS

Процентиль: 95%
0.203
Средний

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via crafted XML with a large number of (1) elements, (2) attributes, (3) nested constructs, and possibly other vectors.

github
больше 3 лет назад

Missing XML Validation in Apache CXF

EPSS

Процентиль: 95%
0.203
Средний

5 Medium

CVSS2