Lucene search

K
ciscoCiscoCISCO-SA-20110928-XCPCUPSXML
HistorySep 28, 2011 - 4:00 p.m.

Jabber Extensible Communications Platform and Cisco Unified Presence XML Denial of Service Vulnerability

2011-09-2816:00:00
tools.cisco.com
13

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

53.4%

A denial of service (DoS) vulnerability exists in Jabber Extensible
Communications Platform (Jabber XCP) and Cisco Unified Presence. An
unauthenticated, remote attacker could exploit this vulnerability by sending
malicious XML to an affected server. Successful exploitation of this
vulnerability could cause elevated memory and CPU utilization, resulting in
memory exhaustion and process crashes. Repeated exploitation could result in a
sustained DoS condition.

There are no workarounds available to mitigate exploitation
of this vulnerability.

This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110928-xcpcupsxml[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110928-xcpcupsxml”].

Affected configurations

Vulners
Node
ciscounified_presence_serverMatchany
OR
ciscojabber_extensible_communications_platformMatchany
OR
ciscounified_presence_serverMatchany
OR
ciscojabber_extensible_communications_platformMatchany

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

53.4%

Related for CISCO-SA-20110928-XCPCUPSXML