PT-2014-6152 · Ibm · Ibm Websphere Commerce
Published
2014-11-05
·
Updated
2019-09-30
·
CVE-2014-4834
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Commerce versions 6.x through 6.0.0.11
IBM WebSphere Commerce versions 7.x through 7.0.0.8
Description
The issue allows remote attackers to cause a denial of service, resulting in memory and CPU consumption, and application crash, via a crafted XML document containing a large number of nested entity references.
Recommendations
For IBM WebSphere Commerce versions 6.x through 6.0.0.11, update to a version that properly detects recursion during entity expansion to prevent denial of service attacks.
For IBM WebSphere Commerce versions 7.x through 7.0.0.8, update to a version that properly detects recursion during entity expansion to prevent denial of service attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Websphere Commerce