Lucene search

K
cveApacheCVE-2022-40705
HistorySep 22, 2022 - 9:15 a.m.

CVE-2022-40705

2022-09-2209:15:09
CWE-611
apache
web.nvd.nist.gov
364
5
cve-2022-40705
apache soap
xml external entity
vulnerability
http
file read

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

38.6%

An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Affected configurations

Nvd
Vulners
Vulnrichment
Node
apachesoapRange2.2
VendorProductVersionCPE
apachesoap*cpe:2.3:a:apache:soap:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Apache SOAP",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "changes": [
          {
            "at": "2.2",
            "status": "unknown"
          }
        ],
        "lessThan": "Apache SOAP*",
        "status": "affected",
        "version": "2.2",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

38.6%