Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-1632


Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.


Published

2010-06-22T20:30:01.493

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm websphere_application_server 7.0 No
Application ibm websphere_application_server 7.0.0.1 No
Application ibm websphere_application_server 7.0.0.2 No
Application ibm websphere_application_server 7.0.0.3 No
Application ibm websphere_application_server 7.0.0.4 No
Application ibm websphere_application_server 7.0.0.5 No
Application ibm websphere_application_server 7.0.0.6 No
Application ibm websphere_application_server 7.0.0.7 No
Application ibm websphere_application_server 7.0.0.8 No
Application ibm websphere_application_server 7.0.0.9 No
Application ibm websphere_application_server 7.0.0.10 No
Application ibm websphere_application_server 7.0.0.11 No
Application ibm websphere_application_server 7.0.0.12 No
Application apache axis2 ≤ 1.5.1 Yes
Application apache axis2 1.3 Yes
Application apache axis2 1.4 Yes
Application apache axis2 1.4.1 Yes
Application apache axis2 1.5 Yes
Application apache axis2 ≤ 1.5.1 Yes
Application apache axis2 1.3 Yes
Application apache axis2 1.4 Yes
Application apache axis2 1.4.1 Yes
Application apache axis2 1.5 Yes
Application apache geronimo * No
Application apache axis2 ≤ 1.5.1 Yes
Application apache axis2 1.3 Yes
Application apache axis2 1.4 Yes
Application apache axis2 1.4.1 Yes
Application apache axis2 1.5 Yes
Application apache orchestration_director_engine * No
Application apache axis2 ≤ 1.5.1 Yes
Application apache axis2 1.3 Yes
Application apache axis2 1.4 Yes
Application apache axis2 1.4.1 Yes
Application apache axis2 1.5 Yes
Application apache synapse * No
Application apache axis2 ≤ 1.5.1 Yes
Application apache axis2 1.3 Yes
Application apache axis2 1.4 Yes
Application apache axis2 1.4.1 Yes
Application apache axis2 1.5 Yes
Application apache tuscany * No

References