U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2013-4002

Change History

Modified Analysis by NIST 9/22/2021 9:54:59 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:ibm:host_on-demand:11.0:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.1:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.2:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.3:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.4:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.5:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.5.1:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.6:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.6.1:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.7:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:host_on-demand:11.0.8:*:*:*:*:*:*:*
     OR
          cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:ibm:sterling_b2b_integrator:5.1:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:sterling_b2b_integrator:5.2:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:sterling_file_gateway:2.1:*:*:*:*:*:*:*
          *cpe:2.3:a:ibm:sterling_file_gateway:2.2:*:*:*:*:*:*:*
     OR
          cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
          cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
          cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
          cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
          cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:-:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:ibm:tivoli_application_dependency_discovery_manager:7.2.2:*:*:*:*:*:*:*
     OR
          cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
          cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
          cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
          cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:-:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:apache:xerces2_java:*:*:*:*:*:*:*:* versions from (including) 2.4.0 up to (excluding) 2.12.0
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:ibm:sterling_b2b_integrator:5.2.4:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:oracle:jdk:1.5.0:update_51:*:*:*:*:*:*
     *cpe:2.3:a:oracle:jdk:1.6.0:update_60:*:*:*:*:*:*
     *cpe:2.3:a:oracle:jdk:1.7.0:update40:*:*:*:*:*:*
     *cpe:2.3:a:oracle:jre:1.5.0:update_51:*:*:*:*:*:*
     *cpe:2.3:a:oracle:jre:1.6.0:update_60:*:*:*:*:*:*
     *cpe:2.3:a:oracle:jre:1.7.0:update_40:*:*:*:*:*:*
     *cpe:2.3:a:oracle:jrockit:*:*:*:*:*:*:*:* versions from (including) r27.7.0 up to (including) r27.7.6
     *cpe:2.3:a:oracle:jrockit:*:*:*:*:*:*:*:* versions from (including) r28.0.0 up to (including) r28.2.8
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
     *cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_desktop:10:sp4:*:*:-:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_java:10:sp4:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_java:11:sp2:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_java:11:sp3:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_sdk:11:sp2:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_sdk:11:sp3:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:ltss:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:-:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
Changed Reference Type
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html No Types Assigned
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html Broken Link, Mailing List
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html No Types Assigned
http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html Third Party Advisory
Changed Reference Type
http://marc.info/?l=bugtraq&m=138674031212883&w=2 No Types Assigned
http://marc.info/?l=bugtraq&m=138674031212883&w=2 Issue Tracking, Mailing List, Third Party Advisory
Changed Reference Type
http://marc.info/?l=bugtraq&m=138674073720143&w=2 No Types Assigned
http://marc.info/?l=bugtraq&m=138674073720143&w=2 Issue Tracking, Mailing List, Third Party Advisory
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1059.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1059.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1060.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1060.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1081.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1081.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1440.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1440.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1447.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1447.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1451.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1451.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-1505.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-1505.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2014-1818.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2014-1818.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2014-1821.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2014-1821.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2014-1822.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2014-1822.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2014-1823.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2014-1823.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2015-0675.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2015-0675.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2015-0720.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2015-0720.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2015-0765.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2015-0765.html Broken Link
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2015-0773.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2015-0773.html Broken Link
Changed Reference Type
http://secunia.com/advisories/56257 No Types Assigned
http://secunia.com/advisories/56257 Third Party Advisory
Changed Reference Type
http://security.gentoo.org/glsa/glsa-201406-32.xml No Types Assigned
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
Changed Reference Type
http://support.apple.com/kb/HT5982 No Types Assigned
http://support.apple.com/kb/HT5982 Third Party Advisory
Changed Reference Type
http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patch No Types Assigned
http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patch Patch, Vendor Advisory
Changed Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg1IC98015 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg1IC98015 Vendor Advisory
Changed Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg21653371 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg21653371 Vendor Advisory
Changed Reference Type
http://www-01.ibm.com/support/docview.wss?uid=swg21657539 No Types Assigned
http://www-01.ibm.com/support/docview.wss?uid=swg21657539 Vendor Advisory
Changed Reference Type
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html No Types Assigned
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html Third Party Advisory
Changed Reference Type
http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002 No Types Assigned
http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002 Vendor Advisory
Changed Reference Type
http://www.ibm.com/support/docview.wss?uid=swg21648172 No Types Assigned
http://www.ibm.com/support/docview.wss?uid=swg21648172 Broken Link
Changed Reference Type
http://www.securityfocus.com/bid/61310 No Types Assigned
http://www.securityfocus.com/bid/61310 Third Party Advisory, VDB Entry
Changed Reference Type
http://www.ubuntu.com/usn/USN-2033-1 No Types Assigned
http://www.ubuntu.com/usn/USN-2033-1 Third Party Advisory
Changed Reference Type
http://www.ubuntu.com/usn/USN-2089-1 No Types Assigned
http://www.ubuntu.com/usn/USN-2089-1 Third Party Advisory
Changed Reference Type
https://access.redhat.com/errata/RHSA-2014:0414 No Types Assigned
https://access.redhat.com/errata/RHSA-2014:0414 Third Party Advisory
Changed Reference Type
https://exchange.xforce.ibmcloud.com/vulnerabilities/85260 No Types Assigned
https://exchange.xforce.ibmcloud.com/vulnerabilities/85260 VDB Entry, Vendor Advisory
Changed Reference Type
https://issues.apache.org/jira/browse/XERCESJ-1679 No Types Assigned
https://issues.apache.org/jira/browse/XERCESJ-1679 Issue Tracking, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73@%3Cj-users.xerces.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73@%3Cj-users.xerces.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html No Types Assigned
https://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html Third Party Advisory