Resource exhaustion in Xerces2 Java XML Parser - CVE-2013-4002

 

Resource exhaustion in Xerces2 Java XML Parser - CVE-2013-4002

Published: October 27, 2023


Vulnerability identifier: #VU82534
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-4002
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Xerces2 Java XML Parser
Jazz Foundation
IBM Business Automation Workflow
App Connect Enterprise Certified Container
IBM SPSS Modeler
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)
IBM Security Verify Governance
IBM Sterling Order Management
Tivoli Network Manager IP Edition
IBM Engineering Systems Design Rhapsody
IBM Engineering Requirements Management DOORS Next
Call Center for Commerce
IBM Content Navigator
Fedora
xerces-j2
IBM Case Manager
Jazz Reporting Service
Operational Decision Manager

How to mitigate CVE-2013-4002

Install updates from vendor's website.

Xerces2 Java XML Parser - update to 2.12.0
IBM Content Navigator - addressed in versions 3.0.15 IF009, 3.1.0 IF008, 3.2.0 IF004
Tivoli Network Manager IP Edition - update to 4.2.0.20
xerces-j2 - update to 2.11.0-22.fc21
IBM Case Manager - update to 5.3.3-IF011
Jazz Reporting Service - update to 7.0.2 iFix022
Jazz Foundation - update to 7.0.2.0.27
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
IBM Cloud Application Performance Management (APM) - addressed in versions 8.1.4.0.14, 8.1.4.0.16
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 36, 8.11.0.1 Interim fix 17, 8.11.0.1 Interim fix 18, 8.11.1 Interim fix 7
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Security Verify Governance - update to 10.0.2
Call Center for Commerce - update to 10.0.2403.1

External References

Related Security Bulletins