4.3
CVSSv2

CVE-2013-5372

Published: 19/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The XML4J parser in IBM WebSphere Message Broker 6.1 prior to 6.1.0.12, 7.0 prior to 7.0.0.7, and 8.0 prior to 8.0.0.4 and IBM Integration Bus 9.0 prior to 9.0.0.1 allows remote malicious users to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere message broker 6.1.0.1

ibm websphere message broker 6.1.0.10

ibm websphere message broker 6.1.0.4

ibm websphere message broker 6.1.0.5

ibm websphere message broker 6.1

ibm websphere message broker 6.1.0.7

ibm websphere message broker 6.1.0.6

ibm websphere message broker 6.1.0.8

ibm websphere message broker 6.1.0.9

ibm websphere message broker 6.1.0.11

ibm websphere message broker 6.1.0.2

ibm websphere message broker 6.1.0.3

ibm websphere message broker 8.0

ibm websphere message broker 8.0.0.1

ibm websphere message broker 8.0.0.2

ibm websphere message broker 8.0.0.3

ibm websphere message broker 7.0.0.3

ibm websphere message broker 7.0.0.4

ibm websphere message broker 7.0.0.5

ibm websphere message broker 7.0.0.6

ibm websphere message broker 7.0.

ibm websphere message broker 7.0.0.1

ibm websphere message broker 7.0.0.2

Vendor Advisories

Synopsis Critical: java-160-ibm security update Type/Severity Security Advisory: Critical Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 5 and 6 SupplementaryThe Red Hat Security Response Team has rated this update as having criticalse ...
Synopsis Low: Red Hat Network Satellite server IBM Java Runtime security update Type/Severity Security Advisory: Low Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Network Satellite Server 54, 55 and 56The Red Hat Security Response Team has rated this ...
Synopsis Critical: java-170-ibm security update Type/Severity Security Advisory: Critical Topic Updated java-170-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 5 and 6 SupplementaryThe Red Hat Security Response Team has rated this update as having criticalse ...
Synopsis Important: java-150-ibm security update Type/Severity Security Advisory: Important Topic Updated java-150-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 5 and 6 SupplementaryThe Red Hat Security Response Team has rated this update as havingimportant ...