Lucene search

K
cvelistRedhatCVELIST:CVE-2013-6440
HistoryFeb 14, 2014 - 3:00 p.m.

CVE-2013-6440

2014-02-1415:00:00
redhat
www.cve.org

6.2 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

6.2 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%