CVE Database
/

CVE-2010-1632

Back to search

CVE-2010-1632

Published: Jun 22, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.

VendorProductVersions

n/a

n/a

affected
n/a

References

PM14844
vendor-advisory
x_refsource_AIXAPAR
ADV-2010-1528
vdb-entry
x_refsource_VUPEN
PM14765
vendor-advisory
x_refsource_AIXAPAR
ADV-2010-1531
vdb-entry
x_refsource_VUPEN
PM14847
vendor-advisory
x_refsource_AIXAPAR
41025
third-party-advisory
x_refsource_SECUNIA
1036901
vdb-entry
x_refsource_SECTRACK
41016
third-party-advisory
x_refsource_SECUNIA
40279
third-party-advisory
x_refsource_SECUNIA
40252
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now