Lucene search

K
cvelistApacheCVELIST:CVE-2021-38555
HistorySep 11, 2021 - 11:05 a.m.

CVE-2021-38555 An XML external entity (XXE) injection vulnerability exists in Apache Any23 StreamUtils.java

2021-09-1111:05:11
apache
www.cve.org
6
apache any23
xxe injection
streamutils.java
security vulnerability
xml data processing

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

50.5%

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application’s processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.

CNA Affected

[
  {
    "product": "Apache Any23",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "2.5",
        "status": "affected",
        "version": "Apache Any23",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

50.5%

Related for CVELIST:CVE-2021-38555