First published: Mon Jun 08 2015(Updated: )
SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an XML document to (1) /agententry, (2) /rdsmonitoringresponse, or (3) /androidactions, aka an XML Entity Expansion (XEE) attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid On-Premises | <=15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3000 is considered a moderate severity vulnerability as it enables denial of service through excessive CPU and memory consumption.
To mitigate CVE-2015-3000, upgrade SysAid Help Desk to version 15.2 or later.
CVE-2015-3000 exploits an XML Entity Expansion (XEE) attack, which results in resource exhaustion.
CVE-2015-3000 affects SysAid Help Desk versions prior to 15.2.
Exploiting CVE-2015-3000 can lead to service disruption due to denial of service caused by high resource utilization.