MEDIUM · 5.0

CVE-2012-4063

The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via ...

Vulnerability Description

The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via unspecified vectors.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
EucalyptusEucalyptus<= 3.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4063?

CVE-2012-4063 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via ...

How severe is CVE-2012-4063?

CVE-2012-4063 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4063?

Check the references section above for vendor advisories and patch information. Affected products include: Eucalyptus Eucalyptus.