CVE-2011-1483 describes a denial-of-service vulnerability in JBossWS Native, affecting various Red Hat JBoss Enterprise platforms and HP products. The flaw, similar to CVE-2003-1564, stems from improper handling of recursion during entity expansion, allowing remote attackers to exhaust memory and CPU resources via crafted XML documents with nested entity references. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it represents a moderate risk due to its network-based attack vector and low complexity, leading to partial availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.11CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_communications_platform:1.2.11:*:*:*:*:*:*:* | ||
5.1.1CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_communications_platform:5.1.1:*:*:*:*:*:*:* | ||
4.2.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp09:*:*:*:*:*:* | ||
4.3.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:*:*:*:*:*:*:* | ||
5.1.1CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.