Vulnerability Name: | CCN-13969 | ||||||
Published: | 2003-10-11 | ||||||
Updated: | 2003-10-11 | ||||||
Summary: | Multiple vendor XML/SOAP HTTP servers are vulnerable to a denial of service. By sending a specially-crafted SOAP request that contains document type definitions (DTDs), a remote attacker could cause the server to consume 100% of the available CPU resources. | ||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||
CVSS v2 Severity: | 7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
| ||||||
Vulnerability Consequences: | Denial of Service | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Dec 11 2003 - 11:58:17 CST Multiple vendor SOAP server (XML parser) denial of service (DTD parameter entities) Source: CCN Type: Microsoft Knowledge Base Article - 826231 Software update to prevent the processing of XML messages that contain DTDs for .NET Framework 1.1 Source: CCN Type: IBM Web site Web Services Denial of Service problem with XML Attributes Source: CCN Type: BID-9185 Multiple Vendor XML Parser SOAP Server Denial Of Service Vulnerability Source: CCN Type: BID-9204 Multiple Vendor XML DTD Parameter Entity SOAP Server Denial Of Service Vulnerability Source: XF Type: UNKNOWN xml-soap-dtd-dos(13969) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |