CVE-2013-4002
Summary
| CVE | CVE-2013-4002 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-23 11:03:19 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names. |
Risk And Classification
Primary CVSS: v2.0 7.1 from [email protected]
AV:N/AC:M/Au:N/C:N/I:N/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:M/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ibm | Aix | - | All | All | All |
| Application | Ibm | Host On-demand | 11.0 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.1 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.2 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.3 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.4 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.5 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.5.1 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.6 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.6.1 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.7 | All | All | All |
| Application | Ibm | Host On-demand | 11.0.8 | All | All | All |
| Application | Ibm | Java | 5.0.0.0 | All | All | All |
| Application | Ibm | Java | 5.0.11.0 | All | All | All |
| Application | Ibm | Java | 5.0.11.1 | All | All | All |
| Application | Ibm | Java | 5.0.11.2 | All | All | All |
| Application | Ibm | Java | 5.0.12.0 | All | All | All |
| Application | Ibm | Java | 5.0.12.1 | All | All | All |
| Application | Ibm | Java | 5.0.12.2 | All | All | All |
| Application | Ibm | Java | 5.0.12.3 | All | All | All |
| Application | Ibm | Java | 5.0.12.4 | All | All | All |
| Application | Ibm | Java | 5.0.12.5 | All | All | All |
| Application | Ibm | Java | 5.0.13.0 | All | All | All |
| Application | Ibm | Java | 5.0.14.0 | All | All | All |
| Application | Ibm | Java | 5.0.15.0 | All | All | All |
| Application | Ibm | Java | 5.0.16.0 | All | All | All |
| Application | Ibm | Java | 5.0.16.1 | All | All | All |
| Application | Ibm | Java | 5.0.16.2 | All | All | All |
| Application | Ibm | Java | 6.0.0.0 | All | All | All |
| Application | Ibm | Java | 6.0.1.0 | All | All | All |
| Application | Ibm | Java | 6.0.10.0 | All | All | All |
| Application | Ibm | Java | 6.0.10.1 | All | All | All |
| Application | Ibm | Java | 6.0.11.0 | All | All | All |
| Application | Ibm | Java | 6.0.12.0 | All | All | All |
| Application | Ibm | Java | 6.0.13.0 | All | All | All |
| Application | Ibm | Java | 6.0.13.1 | All | All | All |
| Application | Ibm | Java | 6.0.13.2 | All | All | All |
| Application | Ibm | Java | 6.0.2.0 | All | All | All |
| Application | Ibm | Java | 6.0.3.0 | All | All | All |
| Application | Ibm | Java | 6.0.4.0 | All | All | All |
| Application | Ibm | Java | 6.0.5.0 | All | All | All |
| Application | Ibm | Java | 6.0.6.0 | All | All | All |
| Application | Ibm | Java | 6.0.7.0 | All | All | All |
| Application | Ibm | Java | 6.0.8.0 | All | All | All |
| Application | Ibm | Java | 6.0.8.1 | All | All | All |
| Application | Ibm | Java | 6.0.9.0 | All | All | All |
| Application | Ibm | Java | 6.0.9.1 | All | All | All |
| Application | Ibm | Java | 6.0.9.2 | All | All | All |
| Application | Ibm | Java | 7.0.0.0 | All | All | All |
| Application | Ibm | Java | 7.0.1.0 | All | All | All |
| Application | Ibm | Java | 7.0.2.0 | All | All | All |
| Application | Ibm | Java | 7.0.3.0 | All | All | All |
| Application | Ibm | Java | 7.0.4.0 | All | All | All |
| Application | Ibm | Java | 7.0.4.1 | All | All | All |
| Application | Ibm | Java | 7.0.4.2 | All | All | All |
| Application | Ibm | Sterling B2b Integrator | 5.2.4 | All | All | All |
| Application | Ibm | Tivoli Application Dependency Discovery Manager | 7.2.2 | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Oracle | Jdk | 1.5.0 | update51 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update60 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update40 | All | All |
| Application | Oracle | Jre | 1.5.0 | update51 | All | All |
| Application | Oracle | Jre | 1.6.0 | update60 | All | All |
| Application | Oracle | Jre | 1.7.0 | update40 | All | All |
| Application | Oracle | Jrockit | All | All | All | All |
| Application | Oracle | Jrockit | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE-SU-2013:1263-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| [security-announce] SUSE-SU-2013:1666-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| Oracle Critical Patch Update Advisory - April 2022 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [security-announce] SUSE-SU-2013:1255-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| IBM Security Bulletin: Rational Host On-Demand clients affected by vulnerabilities in IBM JRE - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| '[security bulletin] HPSBUX02943 rev.1 - HP-UX Running Java6, Remote Unauthorized Access, Disclosure' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Issue Tracking, Mailing List, Third Party Advisory |
| [XERCESJ-1679] xercesImpl: Security threat CVE-2013-4002 - ASF JIRA | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | Issue Tracking, Vendor Advisory |
| '[security bulletin] HPSBUX02944 rev.1 - HP-UX Running Java7, Remote Unauthorized Access, Disclosure' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Issue Tracking, Mailing List, Third Party Advisory |
| Multiple Vulnerabilities in Cosminexus: Software Vulnerability Information: Software: Hitachi | af854a3a-2127-422b-91ae-364da2661108 | www.hitachi.co.jp | Third Party Advisory |
| [security-announce] SUSE-SU-2013:1293-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| openSUSE-SU-2013:1663-1: moderate: update for java-1_7_0-openjdk | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| About the security content of Java for OS X 2013-005 and Mac OS X v10.6 Update 17 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Third Party Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Broken Link |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| IBM Java CVE-2013-4002 Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| IBM IC98015: DENIAL OF SERVICE ATTACK SECURITY VULNERABILITY - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| USN-2033-1: OpenJDK 6 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| [security-announce] SUSE-SU-2013:1305-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| IBM Blogs | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| Gentoo Linux Documentation -- IcedTea JDK: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| Security Advisory SA56257 - IBM Tivoli Application Dependency Discovery Manager Apache XML Parser Denial of Service Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| IBM Security Bulletin: TADDM 7.2.2.0, 7.2.1.5 and 7.2.0.10: Apache Xerces-J XML parser Denial of Service attack. - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| developerWorks : Technical Topics : Java™ technology : IBM Developer kits : Security alerts | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| APPLE-SA-2013-10-15-1 Java for OS X 2013-005 and Mac OS X v10.6 Update 17 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Broken Link, Mailing List |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Broken Link |
| IBM Security Bulletin: Vulnerabilities found in IBM Sterling B2B Integrator and IBM Sterling File Gateway (CVE-2013-4002, CVE-2013-5409, CVE-2013-5405, CVE-2013-5406, CVE-2013-5407, CVE-2013-5411, CVE-2013-5413) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Vendor Advisory |
| [security-announce] SUSE-SU-2013:1256-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| USN-2089-1: OpenJDK 7 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Oracle Critical Patch Update - October 2013 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Third Party Advisory |
| svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanne... | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | Patch, Vendor Advisory |
| [security-announce] SUSE-SU-2013:1257-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.