CVE-2014-4814: Low severity ibm websphere portal vulnerability
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 does not properly detect recursion during entity expansion, which allows remote authenticated users to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4814?
CVE-2014-4814 has a severity rating classified as high due to its potential to cause a denial of service.
How do I fix CVE-2014-4814?
To fix CVE-2014-4814, it is recommended to upgrade to the latest version of IBM WebSphere Portal that includes the security patches.
Who is affected by CVE-2014-4814?
CVE-2014-4814 affects users of IBM WebSphere Portal versions 6.1.0 through 8.5.0 before specified fix packs.
What type of vulnerability is CVE-2014-4814?
CVE-2014-4814 is a denial of service vulnerability caused by improper recursion detection during entity expansion.
Can CVE-2014-4814 be exploited remotely?
Yes, CVE-2014-4814 can be exploited by remote authenticated users to consume system resources.