XML Parsing Vulnerability in IBM WebSphere and Related Products
CVE-2010-1632

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
22 June 2010

Summary

The vulnerability in Apache Axis2 and related products allows attackers to exploit vulnerable configurations by sending crafted SOAP messages that include malicious Document Type Definitions (DTDs). This can lead to unauthorized file access, internal server requests, or denial of service through excessive CPU and memory usage. Such exploitation poses significant risk to the confidentiality, integrity, and availability of affected systems, highlighting the need for timely updates and configuration reviews across the specified products.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.