CVE-2013-4002
published 2013-07-23CVE-2013-4002: XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6…
PriorityP345high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
24.74%
97.7th percentile
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
Affected
84 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xerces2_java | >= 2.4.0 < 2.12.0 | 2.12.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | host_on-demand | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_redhat7.1HIGH
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-01-23·CVSS 6.4
CVE-2013-5817 [MEDIUM] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,
CVE-2013-5804, CVE-2014-0411)
Several vulnerabilities were discovered in the OpenJDK JRE related to
availability. An attacker could exploit these to cause a denial of service.
(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,
CVE-2013-5910)
Several vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,
CVE-2013-5820, CVE-2014-0376, CVE-2014-0416)
Several vulnerabilities we
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2013-11-21·CVSS 6.4
CVE-2013-3829 [MEDIUM] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,
CVE-2013-5804)
Several vulnerabilities were discovered in the OpenJDK JRE related to
availability. An attacker could exploit these to cause a denial of service.
(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825)
Several vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,
CVE-2013-5820)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An atta
Red Hat
OpenJDK: XML parsing Denial of Service (JAXP, 8017298)
vendor_redhat·2013-10-15·CVSS 7.1
CVE-2013-4002 [HIGH] CWE-20 OpenJDK: XML parsing Denial of Service (JAXP, 8017298)
OpenJDK: XML parsing Denial of Service (JAXP, 8017298)
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
A resource consumption issue was found in the way Xerces-J handled XML declarations. A remote attacker could use an XML document with a specially crafted declaration using a long pseudo-attribute name that, when parsed by a
GHSA
Missing XML Validation in Apache Xerces2
ghsa·2022-05-13
CVE-2013-4002 [HIGH] CWE-112 Missing XML Validation in Apache Xerces2
Missing XML Validation in Apache Xerces2
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
OSV
Missing XML Validation in Apache Xerces2
osv·2022-05-13
CVE-2013-4002 [HIGH] Missing XML Validation in Apache Xerces2
Missing XML Validation in Apache Xerces2
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4002 wildfly: Xerces-J2 OpenJDK: XML parsing Denial of Service (JAXP, 8017298) [fedora-all]
bugzilla·2016-09-13·CVSS 7.1
CVE-2013-4002 [HIGH] CVE-2013-4002 wildfly: Xerces-J2 OpenJDK: XML parsing Denial of Service (JAXP, 8017298) [fedora-all]
CVE-2013-4002 wildfly: Xerces-J2 OpenJDK: XML parsing Denial of Service (JAXP, 8017298) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2013-4002 xerces-j2: Xerces-J2 OpenJDK: XML parsing Denial of Service (JAXP, 8017298) [fedora-all]
bugzilla·2014-09-10·CVSS 7.1
CVE-2013-4002 [HIGH] CVE-2013-4002 xerces-j2: Xerces-J2 OpenJDK: XML parsing Denial of Service (JAXP, 8017298) [fedora-all]
CVE-2013-4002 xerces-j2: Xerces-J2 OpenJDK: XML parsing Denial of Service (JAXP, 8017298) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2013-4002 OpenJDK: XML parsing Denial of Service (JAXP, 8017298)
bugzilla·2013-10-15·CVSS 7.1
CVE-2013-4002 [HIGH] CVE-2013-4002 OpenJDK: XML parsing Denial of Service (JAXP, 8017298)
CVE-2013-4002 OpenJDK: XML parsing Denial of Service (JAXP, 8017298)
A denial of service flaw was found in the way the JRE processes XML. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.
Discussion:
The issue was already fixed in IBM Java 5.0 SR16-FP3, 6 SR14, and 7 SR5:
http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013
Public info on the issue is limited to
A denial of service vulnerability in the Apache Xerces-J parser used by IBM
Java could result in a complete availability impact on the affected system.
http://xforce.iss.net/xforce/xfdb/85260
This JRE contains a variant of Apache-J XML parser (XM4J) that is vulnerable
to a denial of service attack triggered by malformed XML data.
http://www-01.ib
Bugzilla
CVE-2013-3006 CVE-2013-3007 CVE-2013-3008 CVE-2013-3009 CVE-2013-3010 CVE-2013-3011 CVE-2013-3012 IBM JDK: Unspecified security fixes (July 2013)
bugzilla·2013-07-17·CVSS 9.3
CVE-2013-3006 [CRITICAL] CVE-2013-3006 CVE-2013-3007 CVE-2013-3008 CVE-2013-3009 CVE-2013-3010 CVE-2013-3011 CVE-2013-3012 IBM JDK: Unspecified security fixes (July 2013)
CVE-2013-3006 CVE-2013-3007 CVE-2013-3008 CVE-2013-3009 CVE-2013-3010 CVE-2013-3011 CVE-2013-3012 IBM JDK: Unspecified security fixes (July 2013)
The July 2013 updates for the IBM JDK (5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5) contain patches for unspecified security flaws.
For the majority of the flaws, upstream has provided a CVSSv2 base score of 9.3, which suggests a CVSSv2 vector of AV:N/AC:M/Au:N/C:P/I:P/A:P. The exception is CVE-2013-4002 with a CVSSv2 base score of 7.1.
CVE CVSSv2 Score Fixed in
CVE-2013-3006 9.3 7 SR5
CVE-2013-3007 9.3 6.0.1 SR6, 7 SR5
CVE-2013-3008 9.3 7 SR5
CVE-2013-3009 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5
CVE-2013-3010 9.3 6.0.1 SR6, 7 SR5
CVE-2013-3011 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5
CVE-2013-3012 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5
CV
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00023.htmlhttp://marc.info/?l=bugtraq&m=138674031212883&w=2http://marc.info/?l=bugtraq&m=138674073720143&w=2http://rhn.redhat.com/errata/RHSA-2013-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1081.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1440.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1447.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1451.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1505.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1818.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1821.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1822.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1823.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0765.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0773.htmlhttp://secunia.com/advisories/56257http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://support.apple.com/kb/HT5982http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patchhttp://www-01.ibm.com/support/docview.wss?uid=swg1IC98015http://www-01.ibm.com/support/docview.wss?uid=swg21644197http://www-01.ibm.com/support/docview.wss?uid=swg21653371http://www-01.ibm.com/support/docview.wss?uid=swg21657539http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.htmlhttp://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013http://www.ibm.com/support/docview.wss?uid=swg21648172http://www.securityfocus.com/bid/61310http://www.ubuntu.com/usn/USN-2033-1http://www.ubuntu.com/usn/USN-2089-1https://access.redhat.com/errata/RHSA-2014:0414https://exchange.xforce.ibmcloud.com/vulnerabilities/85260https://issues.apache.org/jira/browse/XERCESJ-1679https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73%40%3Cj-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00023.htmlhttp://marc.info/?l=bugtraq&m=138674031212883&w=2http://marc.info/?l=bugtraq&m=138674073720143&w=2http://rhn.redhat.com/errata/RHSA-2013-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1081.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1440.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1447.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1451.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1505.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1818.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1821.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1822.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1823.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0765.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0773.htmlhttp://secunia.com/advisories/56257http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://support.apple.com/kb/HT5982http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patchhttp://www-01.ibm.com/support/docview.wss?uid=swg1IC98015http://www-01.ibm.com/support/docview.wss?uid=swg21644197http://www-01.ibm.com/support/docview.wss?uid=swg21653371http://www-01.ibm.com/support/docview.wss?uid=swg21657539http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.htmlhttp://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013http://www.ibm.com/support/docview.wss?uid=swg21648172http://www.securityfocus.com/bid/61310http://www.ubuntu.com/usn/USN-2033-1http://www.ubuntu.com/usn/USN-2089-1https://access.redhat.com/errata/RHSA-2014:0414https://exchange.xforce.ibmcloud.com/vulnerabilities/85260https://issues.apache.org/jira/browse/XERCESJ-1679https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73%40%3Cj-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
2013-07-23
Published