vendor:
ONE Unified Development Server (UDS)
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: ONE Unified Development Server (UDS)
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Sun ONE Unified Development Server (UDS) DTD Handling Denial of Service Vulnerability
It has been reported that problems with the handling of recursive document type definitions (DTDs) occur in Sun ONE Unified Development Server (UDS). When a document is uploaded containing these types of constructs, the system experiences high resource consumption that can result in crash of the system, and denial of service to legitimate users.
Mitigation:
Ensure that the system is configured to reject documents containing recursive DTDs.