Apache CXF XML DTD Processing Security Vulnerability
BID:42492
Info
Apache CXF XML DTD Processing Security Vulnerability
| Bugtraq ID: | 42492 |
| Class: | Unknown |
| CVE: |
CVE-2010-2076 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2010 12:00AM |
| Updated: | Aug 17 2010 06:24PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Apache Geronimo 2.1.5 Apache Geronimo 2.1.4 Apache Geronimo 2.1.3 Apache Geronimo 2.1.2 Apache Geronimo 2.1.1 Apache Geronimo 2.1 Apache Apache CXF 2.2.8 Apache Apache CXF 2.1.9 Apache Apache CXF 2.0.12 |
| Not Vulnerable: |
Apache Geronimo 2.1.6 Apache Apache CXF 2.2.9 Apache Apache CXF 2.1.10 Apache Apache CXF 2.0.13 |
Discussion
Apache CXF XML DTD Processing Security Vulnerability
Apache CXF is prone to a security vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information or cause the affected application to crash, denying service to legitimate users.
Apache CXF versions prior to 2.2.9, 2.1.10 and 2.0.13 are affected.
Apache CXF is prone to a security vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information or cause the affected application to crash, denying service to legitimate users.
Apache CXF versions prior to 2.2.9, 2.1.10 and 2.0.13 are affected.
Exploit / POC
Apache CXF XML DTD Processing Security Vulnerability
Attackers can exploit this issue using browser or readily available tools.
Attackers can exploit this issue using browser or readily available tools.
Solution / Fix
Apache CXF XML DTD Processing Security Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache CXF XML DTD Processing Security Vulnerability
References:
References:
- Apache CXF Homepage (Apache Software Foundation)
- Apache Geronimo v2.1.6 (Apache Software Foundation)
- Apache CXF Security Advisory (CVE-2010-2076) (Apache Software Foundation)