CVE-2013-4002
7.1
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:C
Exploitability: 8.6 / Impact: 6.9
Source: NVD
Description
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Affected (90)
Products: Ibm: Java, Sterling B2b Integrator, Host On Demand, Tivoli Application Dependency Discovery Manager, Sterling File Gateway · Oracle: Jdk, Jre, Jrockit · Opensuse: Opensuse · +3 more
Show all products
Ibm: Java, Sterling B2b Integrator, Host On Demand, Tivoli Application Dependency Discovery Manager, Sterling File Gateway · Oracle: Jdk, Jre, Jrockit · Opensuse: Opensuse · Suse: Linux Enterprise Desktop, Linux Enterprise Java, Linux Enterprise Sdk, Linux Enterprise Server · Canonical: Ubuntu Linux · Apache: Xerces2 Java
Configuration D
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.2.4 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.0.1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.2.2 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.1 | |
| Version 2.1 |
| Running on/with | Platform Versions |
|---|---|
Hp Hp Ux | All versions |
Ibm Aix | All versions |
Ibm I | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
Oracle Solaris | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.2 | |
| Version 10 sp4 | |
| Version 10 sp4 | |
| Version 11 sp2 | |
| Version 10 sp3 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.04 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.4.0 to 2.12.0 |
References (98)
Source: psirt@us.ibm.com
Broken LinkMailing List
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Issue TrackingMailing ListThird Party Advisory
Source: psirt@us.ibm.com
Issue TrackingMailing ListThird Party Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: psirt@us.ibm.com
Third Party Advisory
Source: psirt@us.ibm.com
Vendor Advisory
Source: psirt@us.ibm.com
Vendor Advisory
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
Issue TrackingVendor Advisory
Source: psirt@us.ibm.com
Source: psirt@us.ibm.com
Source: psirt@us.ibm.com
Source: psirt@us.ibm.com
Source: psirt@us.ibm.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.