Lucene search

K
cvelistCertccCVELIST:CVE-2017-3208
HistoryJun 11, 2018 - 5:00 p.m.

CVE-2017-3208

2018-06-1117:00:00
certcc
www.cve.org

9.6 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.5%

The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data on the server, denial of service, or server side request forgery.

9.6 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.5%

Related for CVELIST:CVE-2017-3208