Vulnerability CVE-2015-5038


Published: 2016-01-03

Description:
IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.8/10
6.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
IBM -> Connections 
IBM -> Connections;4.5 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg1LO87020
http://www-01.ibm.com/support/docview.wss?uid=swg21971439

Copyright 2024, cxsecurity.com

 

Back to Top