7.5

CVE-2018-1000632

Exploit

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

Data is provided by the National Vulnerability Database (NVD)
Dom4j ProjectDom4j Version >= 2.0.0 < 2.0.3
Dom4j ProjectDom4j Version >= 2.1.0 < 2.1.1
DebianDebian Linux Version8.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 16.1.0.0 <= 16.2.20.1
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 17.1.0.0 <= 17.12.17.1
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 18.1.0.0 <= 18.8.19.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.6.0
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleRetail Integration Bus Version15.0
OracleRetail Integration Bus Version16.0
OracleUtilities Framework Version >= 4.3.0.2.0 <= 4.3.0.6.0
OracleUtilities Framework Version2.2.0
OracleUtilities Framework Version4.2.0.2.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2
RedhatSatellite Version6.6
RedhatSatellite Capsule Version6.6
RedhatJboss Enterprise Application Platform Version6.0.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Application Platform Version6.4.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
RedhatJboss Enterprise Application Platform Version7.1.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
NetappSnapcenter Version-
NetappSnapmanager Version- SwPlatformoracle
NetappSnapmanager Version- SwPlatformsap
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1% 0.76
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-91 XML Injection (aka Blind XPath Injection)

The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.