Denial of Service Vulnerability in IBM WebSphere Commerce
CVE-2014-4834
Currently unrated
Summary
IBM WebSphere Commerce versions 6.x and 7.x contain a vulnerability that fails to properly handle recursion during entity expansion. This flaw can be exploited by remote attackers through specially crafted XML documents that include a significant number of nested entity references. When this occurs, it may lead to excessive memory and CPU consumption, potentially resulting in application crashes and service interruptions. Organizations utilizing affected versions should verify and implement mitigations to safeguard against such denial of service attacks.
References
Timeline
Vulnerability published
Vulnerability Reserved