HIGH · 7.1

CVE-2013-4002

XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 ...

Vulnerability Description

XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
IbmJava5.0.0.0
OracleJdk1.5.0
OracleJre1.5.0
OracleJrockit>= r27.7.0, <= r27.7.6
IbmSterling B2B Integrator5.2.4
IbmHost On-Demand11.0
MicrosoftWindows-
IbmTivoli Application Dependency Discovery Manager7.2.2
IbmAix-
LinuxLinux Kernel-
OracleSolaris-
IbmSterling File Gateway2.1
HpHp-Ux-
IbmI-
OpensuseOpensuse12.2
SuseLinux Enterprise Desktop10
SuseLinux Enterprise Java10
SuseLinux Enterprise Sdk11
SuseLinux Enterprise Server9
CanonicalUbuntu Linux10.04

References

FAQ

What is CVE-2013-4002?

CVE-2013-4002 is a vulnerability with a CVSS score of 7.1 (HIGH). XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 ...

How severe is CVE-2013-4002?

CVE-2013-4002 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4002?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Java, Oracle Jdk, Oracle Jre, Oracle Jrockit, Ibm Sterling B2B Integrator.