Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-73694
HistorySep 26, 2022 - 12:00 a.m.

Apache SOAP XML External Entity Injection Vulnerability

2022-09-2600:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
apache soap
xml
external entity injection
vulnerability
rpcrouterservlet
attacker
arbitrary files

EPSS

0.001

Percentile

38.6%

Apache SOAP is used as a client-side library by the Apache Foundation to invoke SOAP services available elsewhere, and as a server-side tool to implement SOAP-accessible services. parser in the RPCRouterServlet. An attacker could exploit this vulnerability to read arbitrary files.

EPSS

0.001

Percentile

38.6%