VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 35 minutes ago

CVE-2009-1955

7.5 High Protected by RASP

Description

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

CWE-776 · XML entity expansion

Exploitation Status

Working exploit published

A reviewed exploit catalogue carries this CVE. Somebody has published code a stranger can run.

CVSS E:P

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC 1 indexed Published artifacts you can open, in Exploit-DB; first seen 2009-06-01.
  • EPSS 53% chance in 30 days A model prediction, not an observation. Higher than 99% of all scored CVEs.
IndexArtifactStarsFirst seen
Exploit-DB Apache mod_dav / svn - Remote Denial of Service 2009-06-01

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-776: XML Entity Expansion) can be mitigated by an ARMR xxe security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.

  • Protection full a general security rule for the vulnerability classxxe
  • Action available security rule
  • Review automated inferred
  • Record active
Decided by secure-rule-match : A vulnerability class already blocked by an ARMR security rule
Finding Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-776: XML Entity Expansion) can be mitigated by an ARMR xxe security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.

CVSS

7.5 HIGH v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H NVD Primary published
CVSS 2.0 5.0 no band published AV:N/AC:L/Au:N/C:N/I:N/A:P NVD Primary

Affected Software & Releases

🏛️ Oracle CPU Advisories & Products

AdvisoryTypeQuarterProducts Oracle named in risk matrix
Oracle Critical Patch Update April 2013 CPU 2013-Q2 Oracle Fusion Middleware / Web Listener (-)

Indexed Oracle Components & Versions

FamilyComponentOracle's version cell (verbatim)Indexed as
Oracle Fusion Middleware Web Listener -

🖥️ Product CPEs & Version Ranges

8 product(s) over 13 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd apache apr-util generic < 1.3.7
nvd apache http server generic ≥ 2.2.0 and < 2.2.12
nvd apple mac os x generic < 10.6.2
nvd canonical ubuntu linux generic 6.06 · 8.04 · 8.10 · 9.04
nvd debian debian linux generic 4.0
nvd fedoraproject fedora generic 9 · 10 · 11
nvd oracle http server generic any version
nvd suse linux enterprise server generic 9

References

URLTags
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html Mailing List, Third Party Advisory
http://marc.info/?l=apr-dev&m=124396021826125&w=2 Mailing List, Patch
http://marc.info/?l=bugtraq&m=129190899612998&w=2 Mailing List
http://secunia.com/advisories/34724 Broken Link, Third Party Advisory
http://secunia.com/advisories/35284 Broken Link, Third Party Advisory
http://secunia.com/advisories/35360 Broken Link, Third Party Advisory
http://secunia.com/advisories/35395 Broken Link, Third Party Advisory
http://secunia.com/advisories/35444 Broken Link, Third Party Advisory
http://secunia.com/advisories/35487 Broken Link, Third Party Advisory

Timeline

Published 2009-06-08 Last modified 2026-06-16
Published2009-06-08By the CVE Program.
NVD record modified2026-06-16NVD's own last-modified date for this record.