7.8
CVSSv2

CVE-2015-0132

Published: 18/03/2015 Updated: 18/03/2015
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The XML parser in IBM Rational DOORS Next Generation 4.x prior to 4.0.7 iFix3 and 5.x prior to 5.0.2 and Rational Requirements Composer 2.x and 3.x prior to 3.0.1.6 iFix5 and 4.x prior to 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote malicious users to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm rational requirements composer 3.0.1.2

ibm rational requirements composer 3.0.1.3

ibm rational requirements composer 3.0.1.4

ibm rational requirements composer 3.0.1.5

ibm rational requirements composer 2.0

ibm rational requirements composer 2.0.0.1

ibm rational requirements composer 2.0.0.2

ibm rational requirements composer 2.0.0.3

ibm rational requirements composer 4.0.1

ibm rational requirements composer 4.0.2

ibm rational requirements composer 4.0.3

ibm rational requirements composer 4.0.4

ibm rational requirements composer 3.0

ibm rational requirements composer 3.0.1.1

ibm rational requirements composer 3.0.1.6

ibm rational requirements composer 4.0.0

ibm rational requirements composer 4.0.0.2

ibm rational requirements composer 4.0.5

ibm rational requirements composer 4.0.7

ibm rational requirements composer 2.0.0.4

ibm rational requirements composer 3.0.1

ibm rational requirements composer 4.0

ibm rational requirements composer 4.0.0.1

ibm rational requirements composer 4.0.6

ibm rational doors next generation 4.0.0

ibm rational doors next generation 4.0.1

ibm rational doors next generation 4.0.2

ibm rational doors next generation 4.0.3

ibm rational doors next generation 5.0

ibm rational doors next generation 5.0.1

ibm rational doors next generation 4.0.5

ibm rational doors next generation 4.0.7

ibm rational doors next generation 4.0.4

ibm rational doors next generation 4.0.6