Advisories for Maven/Org.jboss.ws/Jbossws-Common package

2013

Uncontrolled Resource Consumption

wsf/common/DOMUtils.java does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.