Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-2076 | First vendor Publication | 2010-08-19 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 9.8 | ||
Base Score | 9.8 | Environmental Score | 9.8 |
impact SubScore | 5.9 | Temporal Score | 9.8 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2076 |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
67294 | Apache CXF XML SOAP Message Crafted Document Type Declaration Remote DoS |
Snort® IPS/IDS
Date | Description |
---|---|
2014-03-15 | XML exponential entity expansion attack attempt RuleID : 29800 - Revision : 4 - Type : FILE-OTHER |
2014-01-10 | XML entity parsing information disclosure attempt RuleID : 24339 - Revision : 14 - Type : SERVER-WEBAPP |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:07:49 |
|
2024-11-28 12:22:04 |
|
2024-02-16 05:28:14 |
|
2024-02-14 13:28:21 |
|
2023-02-13 09:29:09 |
|
2021-06-16 17:23:13 |
|
2021-05-04 12:12:15 |
|
2021-04-22 01:13:00 |
|
2021-04-02 17:22:45 |
|
2020-11-12 17:22:46 |
|
2020-05-23 00:25:53 |
|
2016-04-26 19:51:28 |
|
2014-11-16 21:24:31 |
|
2013-05-10 23:26:02 |
|