7.8
CVSSv2

CVE-2011-3287

Published: 06/10/2011 Updated: 14/05/2012
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x up to and including 5.4.x prior to 5.4.0.27581 and 5.8.x prior to 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote malicious users to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug ID CSCtq78106, a similar issue to CVE-2003-1564.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco jabber extensible communications platform

cisco jabber extensible communications platform 5.0

cisco jabber extensible communications platform 5.2

cisco jabber extensible communications platform 5.1