CVE-2014-4834 Information
Feb 14, 2021
cve
Description
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion which allows remote attackers to cause a denial of service (memory and CPU consumption and application crash) via a crafted XML document containing a large number of nested entity references a similar issue to CVE-2003-1564.
Reference
http://www.securityfocus.com/bid/70870 http://www-01.ibm.com/support/docview.wss?uid=swg1JR49897 http://www-01.ibm.com/support/docview.wss?uid=swg1JR50553 http://www-01.ibm.com/support/docview.wss?uid=swg21685464 https://exchange.xforce.ibmcloud.com/vulnerabilities/95628
Share on: