Unrated severityNVD Advisory· Published Feb 10, 2014· Updated Apr 29, 2026
CVE-2012-2328
CVE-2012-2328
Description
internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML file.
Affected products
4- cpe:2.3:a:standards_based_linux_instrumentation_project:standards-based_linux_common_information_model_client:*:*:*:*:*:*:*:*Range: <=2.1.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.opensuse.org/opensuse-updates/2012-12/msg00015.htmlnvd
- lists.opensuse.org/opensuse-updates/2013-01/msg00038.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-0987.htmlnvd
- sblim.cvs.sourceforge.net/viewvc/sblim/jsr48-client/src/org/sblim/cimclient/internal/cimxml/sax/NodeFactory.javanvd
- sourceforge.net/p/sblim/bugs/2381/nvd
News mentions
0No linked articles in our index yet.