CVE-2015-5038

HIGH

IBM Connections 3.x < 3.0.1.1 CR3, 4.0 < CR4, 4.5 < CR5, 5.0 < CR3 - Denial of Service via XML Entity Expansion

Title source: llm
STIX 2.1

Description

IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a denial of service (CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21971439
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1LO87020

Scores

CVSS v3 7.5
EPSS 0.0145
EPSS Percentile 70.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (4)
ibm/connections 4.0
ibm/connections 4.5
ibm/connections 5.0
ibm/connections < 3.0.1.1
Published Jan 03, 2016
Tracked Since Feb 18, 2026