Lucene search

K
cve[email protected]CVE-2013-6440
HistoryFeb 14, 2014 - 3:55 p.m.

CVE-2013-6440

2014-02-1415:55:05
CWE-200
web.nvd.nist.gov
62
cve-2013-6440
xml
xxe
security
vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.4 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.8%

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

Affected configurations

NVD
Node
internet2opensamlMatch2.0
OR
internet2opensamlMatch2.1.0
OR
internet2opensamlMatch2.2.0
OR
shibbolethopensamlRange2.6.0
OR
shibbolethopensamlMatch2.4.0
OR
shibbolethopensamlMatch2.4.1
OR
shibbolethopensamlMatch2.4.2
OR
shibbolethopensamlMatch2.4.3
OR
shibbolethopensamlMatch2.5.0
OR
shibbolethopensamlMatch2.5.1
OR
shibbolethopensamlMatch2.5.2
OR
shibbolethopensamlMatch2.5.3

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.4 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.8%