CVE-2010-1632: Input Validation
Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1632?
CVE-2010-1632 is classified as a medium severity vulnerability.
How do I fix CVE-2010-1632?
To fix CVE-2010-1632, upgrade to Apache Axis2 version 1.5.2 or later.
What software is affected by CVE-2010-1632?
CVE-2010-1632 affects Apache Axis2 versions up to 1.5.1, IBM WebSphere Application Server 7.0, and some other related software products.
What happens if I don't mitigate CVE-2010-1632?
Failure to mitigate CVE-2010-1632 may lead to potential unauthorized access or manipulation of web services.
Is there a patch available for CVE-2010-1632?
Yes, upgrading to Apache Axis2 version 1.5.2 or later serves as a patch for CVE-2010-1632.