9.8

CVE-2019-11677

The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Firewall Analyzer Version7.2 Update7020
ZohocorpManageengine Firewall Analyzer Version7.2 Update7021
ZohocorpManageengine Firewall Analyzer Version7.4 Update7400
ZohocorpManageengine Firewall Analyzer Version7.6 Update7600
ZohocorpManageengine Firewall Analyzer Version8.0 Update8000
ZohocorpManageengine Firewall Analyzer Version8.1 Update8110
ZohocorpManageengine Firewall Analyzer Version8.3 Update8300
ZohocorpManageengine Firewall Analyzer Version8.5 Update8500
ZohocorpManageengine Firewall Analyzer Version12.0 Update12000
ZohocorpManageengine Firewall Analyzer Version12.2 Update12200
ZohocorpManageengine Firewall Analyzer Version12.3 Update12300
ZohocorpManageengine Firewall Analyzer Version12.3 Update123008
ZohocorpManageengine Firewall Analyzer Version12.3 Update123027
ZohocorpManageengine Firewall Analyzer Version12.3 Update123045
ZohocorpManageengine Firewall Analyzer Version12.3 Update123057
ZohocorpManageengine Firewall Analyzer Version12.3 Update123064
ZohocorpManageengine Firewall Analyzer Version12.3 Update123070
ZohocorpManageengine Firewall Analyzer Version12.3 Update123083
ZohocorpManageengine Firewall Analyzer Version12.3 Update123092
ZohocorpManageengine Firewall Analyzer Version12.3 Update123126
ZohocorpManageengine Firewall Analyzer Version12.3 Update123129
ZohocorpManageengine Firewall Analyzer Version12.3 Update123137
ZohocorpManageengine Firewall Analyzer Version12.3 Update123151
ZohocorpManageengine Firewall Analyzer Version12.3 Update123156
ZohocorpManageengine Firewall Analyzer Version12.3 Update123164
ZohocorpManageengine Firewall Analyzer Version12.3 Update123169
ZohocorpManageengine Firewall Analyzer Version12.3 Update123177
ZohocorpManageengine Firewall Analyzer Version12.3 Update123182
ZohocorpManageengine Firewall Analyzer Version12.3 Update123185
ZohocorpManageengine Firewall Analyzer Version12.3 Update123186
ZohocorpManageengine Firewall Analyzer Version12.3 Update123194
ZohocorpManageengine Firewall Analyzer Version12.3 Update123197
ZohocorpManageengine Firewall Analyzer Version12.3 Update123208
ZohocorpManageengine Firewall Analyzer Version12.3 Update123218
ZohocorpManageengine Firewall Analyzer Version12.3 Update123222
ZohocorpManageengine Firewall Analyzer Version12.3 Update123223
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.22% 0.883
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.