PT-2013-4781 · Ibm+6 · Ibm Java 7+14

Published

2013-07-15

·

Updated

2024-06-15

·

CVE-2013-4002

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Xerces2 Java Parser versions prior to 2.12.0 IBM Java 5.0 versions prior to 5.0 SR16-FP3 IBM Java 6 versions prior to 6 SR14 IBM Java 6.0.1 versions prior to 6.0.1 SR6 IBM Java 7 versions prior to 7 SR5 Oracle Java SE 7u40 and earlier Oracle Java SE 6u60 and earlier Oracle Java SE 5.0u51 and earlier JRockit R28.2.8 and earlier JRockit R27.7.6 and earlier Java SE Embedded 7u40 and earlier
Description The issue allows remote attackers to cause a denial of service via vectors related to XML attribute names. This is related to the XMLscanner.java in Apache Xerces2 Java Parser.
Recommendations For Apache Xerces2 Java Parser versions prior to 2.12.0, update to version 2.12.0 or later. For IBM Java 5.0 versions prior to 5.0 SR16-FP3, update to 5.0 SR16-FP3 or later. For IBM Java 6 versions prior to 6 SR14, update to 6 SR14 or later. For IBM Java 6.0.1 versions prior to 6.0.1 SR6, update to 6.0.1 SR6 or later. For IBM Java 7 versions prior to 7 SR5, update to 7 SR5 or later. For Oracle Java SE 7u40 and earlier, update to a version later than 7u40. For Oracle Java SE 6u60 and earlier, update to a version later than 6u60. For Oracle Java SE 5.0u51 and earlier, update to a version later than 5.0u51. For JRockit R28.2.8 and earlier, update to a version later than R28.2.8. For JRockit R27.7.6 and earlier, update to a version later than R27.7.6. For Java SE Embedded 7u40 and earlier, update to a version later than 7u40.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01635
CESA-2013_1451
CESA-2013_1505
CESA-2014_1319
CVE-2013-4002
GHSA-7J4H-8WPF-RQFH
HPSBUX02943
HPSBUX02944
MGASA-2013-0322
MGASA-2013-0323
MGASA-2014-0398
OPENSUSE-SU-2024:10534-1
RHSA-2013:1059
RHSA-2013:1060
RHSA-2013:1081
RHSA-2013:1440
RHSA-2013:1447
RHSA-2013:1451
RHSA-2013:1505
RHSA-2013_1059
RHSA-2013_1060
RHSA-2013_1081
RHSA-2013_1440
RHSA-2013_1447
RHSA-2013_1451
RHSA-2013_1505
RHSA-2014:0414
RHSA-2014:1319
RHSA-2014:1818
RHSA-2014:1821
RHSA-2014:1822
RHSA-2014_0414
RHSA-2014_1319

Affected Products

Apache Xerces2 Java Parser
Centos
Hp-Ux
Ibm Java 5.0
Ibm Java 6
Ibm Java 6.0.1
Ibm Java 7
Jrockit
Java Platform
Java Se Embedded 7
Oracle Java Se 5.0
Oracle Java Se 6
Oracle Java Se 7
Red Hat
Suse