PT-2013-1393 · Red Hat · Red Hat Jboss Communications Platform+3

Published

2013-07-28

·

Updated

2022-05-13

·

CVE-2011-1483

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform versions 4.2.0.CP09 through 5.1.1 Red Hat JBoss Enterprise Portal Platform versions 4.3.CP06 through 5.1.1 Red Hat JBoss Enterprise SOA Platform versions 4.2.CP05 through 5.1.0 Red Hat JBoss Communications Platform versions 1.2.11 through 5.1.1 Red Hat JBoss Enterprise BRMS Platform version 5.1.0 Red Hat JBoss Enterprise Web Platform version 5.1.1
Description The issue is related to the handling of recursion during entity expansion in the DOMUtils.java file. This allows remote attackers to cause a denial of service by consuming memory and CPU via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references.
Recommendations For Red Hat JBoss Enterprise Application Platform versions 4.2.0.CP09 through 5.1.1, consider disabling the DOMUtils.java functionality until a patch is available. For Red Hat JBoss Enterprise Portal Platform versions 4.3.CP06 through 5.1.1, restrict access to the org.jboss.ws:jbossws-common module to minimize the risk of exploitation. For Red Hat JBoss Enterprise SOA Platform versions 4.2.CP05 through 5.1.0, avoid using the DOMUtils.java file in the affected API endpoint until the issue is resolved. For Red Hat JBoss Communications Platform versions 1.2.11 through 5.1.1, consider temporarily disabling the jbossws-common functionality to prevent exploitation. For Red Hat JBoss Enterprise BRMS Platform version 5.1.0 and Red Hat JBoss Enterprise Web Platform version 5.1.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1483
GHSA-RJ4P-7MM6-GM9J
RHSA-2011:1301
RHSA-2011:1303
RHSA-2011:1306
RHSA-2011:1309

Affected Products

Red Hat Jboss Communications Platform
Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Enterprise Soa Platform
Red Hat Jboss Enterprise Portal Platform