5
CVSSv2

CVE-2011-1483

Published: 29/07/2013 Updated: 09/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0; and JBoss Enterprise Web Platform 5.1.1 does not properly handle recursion during entity expansion, which allows remote malicious users to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise portal platform 4.3.0

redhat jboss enterprise soa platform 4.2.0

redhat jboss enterprise soa platform 5.1.0

redhat jboss communications platform 1.2.11

redhat jboss communications platform 5.1.1

redhat jboss enterprise brms platform 5.1.0

redhat jboss enterprise application platform 4.2.0

redhat jboss enterprise application platform 4.3.0

redhat jboss enterprise application platform 5.1.1

redhat jboss enterprise portal platform 5.1.1

redhat jboss enterprise soa platform 4.3.0

redhat jboss enterprise web platform 5.1.1

hp network node manager i 9.02

hp network node manager i 9.0

hp network node manager i 9.10

hp network node manager i 9.03

hp network node manager i 9.01