CVE-2011-3287
Cisco Jabber Extensible Communications Platform 2.x-5.4.x - Denial of Service via XML Entity Expansion
Title source: llmDescription
Cisco Jabber Extensible Communications Platform (aka Jabber XCP) 2.x through 5.4.x before 5.4.0.27581 and 5.8.x before 5.8.1.27561 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug ID CSCtq78106, a similar issue to CVE-2003-1564.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d47.shtml
Scores
EPSS
0.0120
EPSS Percentile
65.1%
Details
CWE
CWE-399
Status
published
Products (4)
cisco/jabber_extensible_communications_platform
5.0
cisco/jabber_extensible_communications_platform
5.1
cisco/jabber_extensible_communications_platform
5.2
cisco/jabber_extensible_communications_platform
< 5.8
Published
Oct 06, 2011
Tracked Since
Feb 18, 2026