Resource exhaustion in Xerces2 Java XML Parser - CVE-2013-4002
Published: October 27, 2023
Vulnerability identifier: #VU82534
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4002
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Xerces2 Java XML Parser
Jazz Foundation
IBM Business Automation Workflow
App Connect Enterprise Certified Container
IBM SPSS Modeler
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Sterling Order Management
Tivoli Network Manager IP Edition
IBM Engineering Systems Design Rhapsody
IBM Engineering Requirements Management DOORS Next
Call Center for Commerce
IBM Content Navigator
Fedora
xerces-j2
IBM Case Manager
Jazz Reporting Service
Operational Decision Manager
Jazz Foundation
IBM Business Automation Workflow
App Connect Enterprise Certified Container
IBM SPSS Modeler
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Sterling Order Management
Tivoli Network Manager IP Edition
IBM Engineering Systems Design Rhapsody
IBM Engineering Requirements Management DOORS Next
Call Center for Commerce
IBM Content Navigator
Fedora
xerces-j2
IBM Case Manager
Jazz Reporting Service
Operational Decision Manager
How to mitigate CVE-2013-4002
Install updates from vendor's website.
Xerces2 Java XML Parser - update to 2.12.0
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
Tivoli Network Manager IP Edition - update to 4.2.0.20
xerces-j2 - update to 2.11.0-22.fc21
IBM Case Manager - update to 5.3.3-IF011
Jazz Reporting Service - update to 7.0.2 iFix022
Jazz Foundation - update to 7.0.2.0.27
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.14, 8.1.4.0.16
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 36, 8.11.0.1 Interim fix 17, 8.11.0.1 Interim fix 18, 8.11.1 Interim fix 7
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Security Verify Governance - update to 10.0.2
Call Center for Commerce - update to 10.0.2403.1
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
Tivoli Network Manager IP Edition - update to 4.2.0.20
xerces-j2 - update to 2.11.0-22.fc21
IBM Case Manager - update to 5.3.3-IF011
Jazz Reporting Service - update to 7.0.2 iFix022
Jazz Foundation - update to 7.0.2.0.27
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.14, 8.1.4.0.16
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 36, 8.11.0.1 Interim fix 17, 8.11.0.1 Interim fix 18, 8.11.1 Interim fix 7
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Security Verify Governance - update to 10.0.2
Call Center for Commerce - update to 10.0.2403.1
External References
- http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013
- http://www-01.ibm.com/support/docview.wss?uid=swg21644197
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
- http://rhn.redhat.com/errata/RHSA-2013-1081.html
- http://rhn.redhat.com/errata/RHSA-2013-1060.html
- http://www.securityfocus.com/bid/61310
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002
- http://www.ibm.com/support/docview.wss?uid=swg21648172
- http://rhn.redhat.com/errata/RHSA-2013-1440.html
- http://rhn.redhat.com/errata/RHSA-2013-1451.html
- http://rhn.redhat.com/errata/RHSA-2013-1447.html
- http://support.apple.com/kb/HT5982
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html
- http://www.ubuntu.com/usn/USN-2033-1
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html
- http://rhn.redhat.com/errata/RHSA-2013-1505.html
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC98015
- http://www-01.ibm.com/support/docview.wss?uid=swg21657539
- http://marc.info/?l=bugtraq&m=138674073720143&w=2
- http://marc.info/?l=bugtraq&m=138674031212883&w=2
- http://www-01.ibm.com/support/docview.wss?uid=swg21653371
- http://secunia.com/advisories/56257
- http://rhn.redhat.com/errata/RHSA-2013-1059.html
- http://www.ubuntu.com/usn/USN-2089-1
- http://security.gentoo.org/glsa/glsa-201406-32.xml
- http://rhn.redhat.com/errata/RHSA-2014-1822.html
- http://rhn.redhat.com/errata/RHSA-2014-1818.html
- http://rhn.redhat.com/errata/RHSA-2014-1821.html
- http://rhn.redhat.com/errata/RHSA-2014-1823.html
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://rhn.redhat.com/errata/RHSA-2015-0765.html
- http://rhn.redhat.com/errata/RHSA-2015-0773.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85260
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
- https://access.redhat.com/errata/RHSA-2014:0414
- https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73@%3Cj-users.xerces.apache.org%3E
- https://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
- https://issues.apache.org/jira/browse/XERCESJ-1679
- http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patch
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2022.html
Related Security Bulletins
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Multiple vulnerabilities in IBM Jazz Reporting Service
- Multiple vulnerabilities in IBM Tivoli Composite Application Manager (ITCAM) for Transactions
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM Call Center for Commerce
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Jazz Foundation
- Multiple vulnerabilities in IBM Application Performance Management products
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Application Performance Management
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition (ITNM)
- Fedora 21 update for xerces-j2
- Multiple vulnerabilities in IBM Content Navigator
- Multiple vulnerabilities in IBM SPSS Modeler