CVE-2018-1000632

Aliases:GHSA-6pcc-3rfx-4gpm
Modified
Published: 20 Aug 2018, 19:00
Last modified:05 Aug 2024, 12:40

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
1.61% LOW
2% probability -0.04%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

20 Aug 2018, 19:00
Published
Vulnerability first disclosed
05 Aug 2024, 12:40
Last Modified
Vulnerability information updated

Description

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 1.61% Percentile: 82%

Techniques & Countermeasures

  • CWE-91XML Injection (aka Blind XPath Injection)

    The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.

Affected Systems

  • debiandebian_linux

    8.0

  • dom4j_projectdom4j

    ≥ 2.0.0, < 2.0.3 | ≥ 2.1.0, < 2.1.1

  • dom4jdom4j

    ≤ 1.6.1

  • org.dom4jdom4j

    < 2.0.3 | ≥ 2.1.0, < 2.1.1

  • netapponcommand_workflow_automation

    na

  • netappsnap_creator_framework

    na

  • netappsnapcenter

    na

  • netappsnapmanager

    na

  • oracleflexcube_investor_servicing

    12.0.4 | 12.1.0 | 12.3.0 | 12.4.0 | 14.0.0

  • oracleprimavera_p6_enterprise_project_portfolio_management

    ≥ 16.1.0.0, ≤ 16.2.20.1 | ≥ 17.1.0.0, ≤ 17.12.17.1 | ≥ 18.1.0.0, ≤ 18.8.19.0 | ≥ 19.12.0.0, ≤ 19.12.6.0

  • oraclerapid_planning

    12.1 | 12.2

  • oracleretail_integration_bus

    15.0 | 16.0

  • oracleutilities_framework

    ≥ 4.3.0.2.0, ≤ 4.3.0.6.0 | 2.2.0 | 4.2.0.2.0 | 4.2.0.3.0 | 4.4.0.0.0 | 4.4.0.2

  • redhatjboss_enterprise_application_platform

    6.0.0 | 6.4.0 | 7.1.0

  • redhatsatellite

    6.6

  • redhatsatellite_capsule

    6.6

References (46)