Apache Axis2 Document Type Declaration Processing Security Vulnerability

BID:40976

Info

Apache Axis2 Document Type Declaration Processing Security Vulnerability

Bugtraq ID: 40976
Class: Design Error
CVE: CVE-2010-1632
Remote: Yes
Local: No
Published: Jun 13 2010 12:00AM
Updated: Sep 28 2016 12:02AM
Credit: Jan Freitag
Vulnerable: IBM Websphere Application Server Feat Pack for Web 2.0 1.0.1 .0
IBM Websphere Application Server 7.0 3
IBM Websphere Application Server 7.0 .9
IBM Websphere Application Server 7.0 .8
IBM Websphere Application Server 7.0 .12
IBM Websphere Application Server 7.0 .11
IBM Websphere Application Server 6.1 .9
IBM Websphere Application Server 6.1 .32
IBM Websphere Application Server 6.1 .25
IBM Websphere Application Server 6.1 .23
IBM Websphere Application Server 6.1 .22
IBM Websphere Application Server 6.1 .21
IBM Websphere Application Server 6.1 .20
IBM Websphere Application Server 6.1 .19
IBM Websphere Application Server 6.1 .18
IBM Websphere Application Server 6.1 .17
IBM Websphere Application Server 6.1 .15
IBM Websphere Application Server 6.1 .14
IBM Websphere Application Server 6.1 .13
IBM Websphere Application Server 6.1 .12
IBM Websphere Application Server 6.1 .11
IBM Websphere Application Server 6.1 .10
IBM Websphere Application Server 7.0.0.7
IBM Websphere Application Server 7.0.0.5
IBM Websphere Application Server 7.0.0.1
IBM Websphere Application Server 7.0
IBM Websphere Application Server 6.1.0.31
IBM Websphere Application Server 6.1.0.29
IBM Websphere Application Server 6.1.0.27
IBM FileNet Services for Lotus Quickr 1.1
IBM Content Manager Services for Lotus Quickr Axis2 1.1
IBM Content Integrator 8.5.1
HP JG768AAE HP PCM+ to IMC Std Upg w/ 200-node E-LTU 0
HP JG767AAE HP IMC SmCnct WSM Vrtl Applnc SW E-LTU 0
HP JG766AAE HP IMC SmCnct Vrtl Applnc SW E-LTU 0
HP JG748AAE HP IMC Ent SW Plat w/ 50 Nodes E-LTU 0
HP JG747AAE HP IMC Std SW Plat w/ 50 Nodes E-LTU 0
HP JG660AAE HP IMC Smart Connect w/WLM VAE E-LTU 0
HP JG590AAE HP IMC Bsc WLAN Mgr SW Pltfm 50 AP E-LTU 0
HP JG550AAE HP PMM to IMC Bsc WLM Upgr w/150AP E-LTU 0
HP JG549AAE HP PCM+ to IMC Std Upgr w/200-node E-LTU 0
HP JG548AAE HP PCM+ to IMC Bsc Upgr w/50-node E-LTU 0
HP JG546AAE HP IMC Basic SW Platform w/50-node E-LTU 0
HP JF378AAE HP IMC Ent S/W Pltfrm w/200-node E-LTU 0
HP JF378A HP IMC Ent S/W Platform w/200-node Lic 0
HP JF377AAE HP IMC Std S/W Pltfrm w/100-node E-LTU 0
HP JF377A HP IMC Std S/W Platform w/100-node Lic 0
HP JF289AAE HP Enterprise Management System to Intelligent Manageme 0
HP JF288AAE HP Network Director to Intelligent Management Center 0
HP JD816A HP A-IMC Standard Edition Software DVD Media 0
HP JD815A HP IMC Std Platform w/100-node License 0
HP JD814A HP A-IMC Enterprise Edition Software DVD Media 0
HP JD808A HP IMC Ent Platform w/100-node License 0
HP JD126A HP IMC Ent S/W Platform w/100-node 0
HP JD125A HP IMC Std S/W Platform w/100-node 0
Apache Geronimo 2.1.5
Apache Geronimo 2.1.4
Apache Geronimo 2.1.3
Apache Geronimo 2.1.2
Apache Geronimo 2.1.1
Apache Geronimo 2.1
Apache Axis2 1.5.1
Apache Axis2 1.4.1
Not Vulnerable: IBM Websphere Application Server Feat Pack for Web 2.0 1.0.1 .1
IBM Websphere Application Server 7.0 .13
IBM Websphere Application Server 6.1 .33
IBM FileNet Services for Lotus Quickr Version 1.1 Fix Pack 1 0
IBM Content Manager Services for Lotus Quickr Axis2 Version 1.1 Fix 0
Apache Geronimo 2.1.6
Apache Axis2 1.5.2
Apache Axis2 1.6

Discussion

Apache Axis2 Document Type Declaration Processing Security Vulnerability

Apache Axis2 is prone to a security vulnerability that may result in information-disclosure or denial-of-service conditions.

An attacker can exploit this vulnerability to obtain potentially sensitive information by including local and external files on computers running the vulnerable application or by causing denial-of-service conditions; other attacks are also possible.

The issue affects versions prior to 1.5.2 and 1.6.

Exploit / POC

Apache Axis2 Document Type Declaration Processing Security Vulnerability

Attackers may exploit this issue using standard readily-available tools.

Solution / Fix

Apache Axis2 Document Type Declaration Processing Security Vulnerability

Solution:
The vendor has released fixes. Please see the references for more information.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report