Multiple Vendor XML DTD Parameter Entity SOAP Server Denial Of Service Vulnerability
BID:9204
Info
Multiple Vendor XML DTD Parameter Entity SOAP Server Denial Of Service Vulnerability
| Bugtraq ID: | 9204 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2003 12:00AM |
| Updated: | Dec 11 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Amit Klein <[email protected]>. |
| Vulnerable: |
Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.0 SP1 Microsoft .NET Framework 1.0 IBM Websphere Application Server 5.0 |
| Not Vulnerable: | |
Discussion
Multiple Vendor XML DTD Parameter Entity SOAP Server Denial Of Service Vulnerability
A problem has been identified in several different SOAP servers when handling certain types of SOAP requests.
The problem is in the handling of SOAP requests that contain references to DTD parameter entities. By making a SOAP request with maliciously crafted DTD data, it is possible to trigger a prolonged denial of web services.
A problem has been identified in several different SOAP servers when handling certain types of SOAP requests.
The problem is in the handling of SOAP requests that contain references to DTD parameter entities. By making a SOAP request with maliciously crafted DTD data, it is possible to trigger a prolonged denial of web services.
Exploit / POC
Multiple Vendor XML DTD Parameter Entity SOAP Server Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor XML DTD Parameter Entity SOAP Server Denial Of Service Vulnerability
Solution:
IBM have released an advisory (PQ70921) and fixes to address these issues in WebSphere App Server version 5. Please see attached advisory for further details regarding obtaining and applying relative fixes.
Microsoft have reportedly released a Knowledge Base article 826231 to address this issue, however it should be noted that this article was not available at the time of writing:
http://support.microsoft.com/default.aspx?kbid=826231
IBM Websphere Application Server 5.0
Solution:
IBM have released an advisory (PQ70921) and fixes to address these issues in WebSphere App Server version 5. Please see attached advisory for further details regarding obtaining and applying relative fixes.
Microsoft have reportedly released a Knowledge Base article 826231 to address this issue, however it should be noted that this article was not available at the time of writing:
http://support.microsoft.com/default.aspx?kbid=826231
IBM Websphere Application Server 5.0
-
IBM PQ70921_Fix.jar
ftp://ftp.software.ibm.com/software/websphere/appserv/support/fixes/PQ 70921/
References
Multiple Vendor XML DTD Parameter Entity SOAP Server Denial Of Service Vulnerability
References:
References: