CVE-2013-4002

high
Published 2013-07-23 · Modified 2024-12-03
CVSS v3
CVSS v2
7.1
VIR risk
7.1

Description

Missing XML Validation in Apache Xerces2

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — https://issues.apache.org/jira/browse/XERCESJ-1679

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — https://exchange.xforce.ibmcloud.com/vulnerabilities/85260

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21657539

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21653371

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21644197

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IC98015

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patch

OS impact

OSVersionStatusFixed in
linux linux-kernel-not-affected
ubuntu ubuntu10.04affected
ubuntu ubuntu12.04affected
ubuntu ubuntu12.10affected
ubuntu ubuntu13.04affected
ubuntu ubuntu13.10affected
suse suse12.2affected
suse suse12.3affected
suse suse10affected
suse suse11affected
suse suse9affected

Package impact

EcosystemPackageVulnerableFixed
java Mavenxerces:xercesImpl<2.12.02.12.0

Application impact

VendorProductVersionsFixed
ibmjava5.0.0.0
ibmjava5.0.11.0
ibmjava5.0.11.1
ibmjava5.0.11.2
ibmjava5.0.12.0
ibmjava5.0.12.1
ibmjava5.0.12.2
ibmjava5.0.12.3
ibmjava5.0.12.4
ibmjava5.0.12.5
ibmjava5.0.13.0
ibmjava5.0.14.0
ibmjava5.0.15.0
ibmjava5.0.16.0
ibmjava5.0.16.1
ibmjava5.0.16.2
ibmjava6.0.0.0
ibmjava6.0.1.0
ibmjava6.0.2.0
ibmjava6.0.3.0
ibmjava6.0.4.0
ibmjava6.0.5.0
ibmjava6.0.6.0
ibmjava6.0.7.0
ibmjava6.0.8.0
ibmjava6.0.8.1
ibmjava6.0.9.0
ibmjava6.0.9.1
ibmjava6.0.9.2
ibmjava6.0.10.0
ibmjava6.0.10.1
ibmjava6.0.11.0
ibmjava6.0.12.0
ibmjava6.0.13.0
ibmjava6.0.13.1
ibmjava6.0.13.2
ibmjava7.0.0.0
ibmjava7.0.1.0
ibmjava7.0.2.0
ibmjava7.0.3.0
ibmjava7.0.4.0
ibmjava7.0.4.1
ibmjava7.0.4.2
oraclejdk1.5.0
oraclejdk1.6.0
oraclejdk1.7.0
oraclejre1.5.0
oraclejre1.6.0
oraclejre1.7.0
oraclejrockit{"startIncluding":"r27.7.0","endIncluding":"r27.7.6"}
ibmsterling_b2b_integrator5.2.4
ibmhost_on-demand11.0
ibmhost_on-demand11.0.1
ibmhost_on-demand11.0.2
ibmhost_on-demand11.0.3
ibmhost_on-demand11.0.4
ibmhost_on-demand11.0.5
ibmhost_on-demand11.0.5.1
ibmhost_on-demand11.0.6
ibmhost_on-demand11.0.6.1
ibmhost_on-demand11.0.7
ibmhost_on-demand11.0.8
ibmtivoli_application_dependency_discovery_manager7.2.2
ibmsterling_b2b_integrator5.1
ibmsterling_b2b_integrator5.2
ibmsterling_file_gateway2.1
ibmsterling_file_gateway2.2
apache apachexerces2_java{"startIncluding":"2.4.0","endExcluding":"2.12.0"}2.12.0

References

Verify integrity in audit chain (admin only). AS-IS.