PT-2025-38131 · Xen+2 · Xapi+1
CVSS v4.0
9.4
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
XAPI (affected versions not specified)
Description
Multiple issues in XAPI can lead to a Denial of Service. First, while updates to the database sanitize input strings, the notification generation process uses unsanitized input, which can cause the database event thread to terminate and stop processing. Second, a discrepancy between the UTF-8 encoder (Unicode spec v3.0) and other internal libraries (Unicode spec v3.1) allows certain strings to be accepted and stored in the database, which subsequently prevents the database from being loaded. Third, there is a lack of input sanitization for Map/Set updates on objects within the database.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xapi
Xen