← Back

CVE-2010-1632

nvd nist
Published: Jun 22, 2010Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.

Affected (5)

Products: Apache: Axis2
1 product
Axis2
Configuration A
13 platform
Running on/withPlatform Versions
Ibm
Websphere Application Server
Version 7.0.0.10
Ibm
Websphere Application Server
Version 7.0.0.11
Ibm
Websphere Application Server
Version 7.0.0.12
Ibm
Websphere Application Server
Version 7.0.0.1
Ibm
Websphere Application Server
Version 7.0.0.2
Ibm
Websphere Application Server
Version 7.0.0.3
Ibm
Websphere Application Server
Version 7.0.0.4
Ibm
Websphere Application Server
Version 7.0.0.5
Ibm
Websphere Application Server
Version 7.0.0.6
Ibm
Websphere Application Server
Version 7.0.0.7
Ibm
Websphere Application Server
Version 7.0.0.8
Ibm
Websphere Application Server
Version 7.0.0.9
Ibm
Websphere Application Server
Version 7.0
Configuration B
1 platform
Running on/withPlatform Versions
Apache
Geronimo
All versions
Configuration C
1 platform
Running on/withPlatform Versions
Apache
Orchestration Director Engine
All versions
Configuration D
1 platform
Running on/withPlatform Versions
Apache
Synapse
All versions
Configuration E
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Apache
Up to 1.5.1
Version 1.3
Version 1.4.1
Version 1.4
Version 1.5
Running on/withPlatform Versions
Apache
Tuscany
All versions

References (38)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.