CVE-2012-0881

Description

Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.942

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2013-4002,CVE-2012-0881 are fixed in Apache-xercesImpl 2.12.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0.0.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.2.0.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.3.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.4.0Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 21.0.3.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 22.0.2Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.3Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.11Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.10Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.4Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.9Windows
xerces-j2 Security Update (ALAS-2024-2649) xerces-j2-javadoc-2.11.0-17.amzn2.0.2.noarch.rpmLinux
xerces-j2 Security Update (ALAS-2024-2649) xerces-j2-demo-2.11.0-17.amzn2.0.2.noarch.rpmLinux
xerces-j2 Security Update (ALAS-2024-2649) xerces-j2-2.11.0-17.amzn2.0.2.noarch.rpmLinux
Vulnerabilities CVE-2013-4002,CVE-2012-0881 are fixed in Apache-xercesImpl for Linux 2.12.0Linux
xerces-j2 Security Update (ALAS2-2024-2649) xerces-j2-2.11.0-17.amzn2.0.2.noarch.rpmLinux
xerces-j2 Security Update (ALAS2-2024-2649) xerces-j2-demo-2.11.0-17.amzn2.0.2.noarch.rpmLinux
xerces-j2 Security Update (ALAS2-2024-2649) xerces-j2-javadoc-2.11.0-17.amzn2.0.2.noarch.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234