7.1
CVE-2013-4002
- EPSS 24.74%
- Veröffentlicht 23.07.2013 11:03:19
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Sterling B2b Integrator Version 5.2.4
Ibm ≫ Host On-demand Version 11.0
Ibm ≫ Host On-demand Version 11.0.1
Ibm ≫ Host On-demand Version 11.0.2
Ibm ≫ Host On-demand Version 11.0.3
Ibm ≫ Host On-demand Version 11.0.4
Ibm ≫ Host On-demand Version 11.0.5
Ibm ≫ Host On-demand Version 11.0.5.1
Ibm ≫ Host On-demand Version 11.0.6
Ibm ≫ Host On-demand Version 11.0.6.1
Ibm ≫ Host On-demand Version 11.0.7
Ibm ≫ Host On-demand Version 11.0.8
Ibm ≫ Tivoli Application Dependency Discovery Manager Version 7.2.2
Ibm ≫ Sterling B2b Integrator Version 5.1
Ibm ≫ Sterling B2b Integrator Version 5.2
Ibm ≫ Sterling File Gateway Version 2.1
Ibm ≫ Sterling File Gateway Version 2.2
Suse ≫ Linux Enterprise Desktop Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Linux Enterprise Java Version 10 Update sp4
Suse ≫ Linux Enterprise Java Version 11 Update sp2
Suse ≫ Linux Enterprise Java Version 11 Update sp3
Suse ≫ Linux Enterprise Sdk Version 11 Update sp2
Suse ≫ Linux Enterprise Sdk Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 9
Suse ≫ Linux Enterprise Server Version 10 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition -
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwPlatform vmware
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.04
Canonical ≫ Ubuntu Linux Version 13.10
Apache ≫ Xerces2 Java Version >= 2.4.0 < 2.12.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 24.74% | 0.976 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:C
|
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
http://security.gentoo.org/glsa/glsa-201406-32.xml
https://www.oracle.com/security-alerts/cpuapr2022.html
http://www-01.ibm.com/support/docview.wss?uid=swg21644197
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html
http://rhn.redhat.com/errata/RHSA-2013-1059.html
http://rhn.redhat.com/errata/RHSA-2013-1060.html
http://rhn.redhat.com/errata/RHSA-2013-1081.html
https://access.redhat.com/errata/RHSA-2014:0414
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html
http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html
http://marc.info/?l=bugtraq&m=138674031212883&w=2
http://marc.info/?l=bugtraq&m=138674073720143&w=2
http://rhn.redhat.com/errata/RHSA-2013-1440.html
http://rhn.redhat.com/errata/RHSA-2013-1447.html
http://rhn.redhat.com/errata/RHSA-2013-1451.html
http://rhn.redhat.com/errata/RHSA-2013-1505.html
http://rhn.redhat.com/errata/RHSA-2014-1818.html
http://rhn.redhat.com/errata/RHSA-2014-1821.html
http://rhn.redhat.com/errata/RHSA-2014-1822.html
http://rhn.redhat.com/errata/RHSA-2014-1823.html
http://rhn.redhat.com/errata/RHSA-2015-0675.html
http://rhn.redhat.com/errata/RHSA-2015-0720.html
http://rhn.redhat.com/errata/RHSA-2015-0765.html
http://rhn.redhat.com/errata/RHSA-2015-0773.html
http://secunia.com/advisories/56257
http://support.apple.com/kb/HT5982
http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patch
http://www-01.ibm.com/support/docview.wss?uid=swg1IC98015
http://www-01.ibm.com/support/docview.wss?uid=swg21653371
http://www-01.ibm.com/support/docview.wss?uid=swg21657539
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html
http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002
http://www.ibm.com/support/docview.wss?uid=swg21648172
http://www.securityfocus.com/bid/61310
http://www.ubuntu.com/usn/USN-2033-1
http://www.ubuntu.com/usn/USN-2089-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/85260
https://issues.apache.org/jira/browse/XERCESJ-1679
https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73%40%3Cj-users.xerces.apache.org%3E
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
https://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html