Lucene search

K
cveAdobeCVE-2019-7847
HistoryJul 18, 2019 - 10:15 p.m.

CVE-2019-7847

2019-07-1822:15:12
CWE-611
adobe
web.nvd.nist.gov
73
adobe campaign classic
xxe vulnerability
cve-2019-7847
nvd
security issue

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

58.2%

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference (‘XXE’) vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.

Affected configurations

Nvd
Vulners
Node
adobecampaignRange18.10.5.8984classic
AND
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
VendorProductVersionCPE
adobecampaign*cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoftwindows-cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Adobe Campaign",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Adobe Campaign Classic 18.10.5-8984 and earlier versions"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.1

Confidence

High

EPSS

0.002

Percentile

58.2%

Related for CVE-2019-7847