Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x up to and including 5.4.x prior to 5.4.0.27581 and 5.8.x prior to 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote malicious users to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug ID CSCtq78106, a similar issue to CVE-2003-1564.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco jabber extensible communications platform |
||
cisco jabber extensible communications platform 5.0 |
||
cisco jabber extensible communications platform 5.2 |
||
cisco jabber extensible communications platform 5.1 |