Lucene search

K
githubGitHub Advisory DatabaseGHSA-JQ8C-J47C-VVWM
HistorySep 23, 2022 - 12:00 a.m.

Apache SOAP's RPCRouterServlet allows reading of arbitrary files over HTTP

2022-09-2300:00:46
CWE-611
GitHub Advisory Database
github.com
17
apache soap
rpcrouterservlet
xml external entity reference
vulnerability
arbitrary files
http
version 2.2
unsupported products

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

38.6%

An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected configurations

Vulners
Node
soapsoapRange2.22.3.1
VendorProductVersionCPE
soapsoap*cpe:2.3:a:soap:soap:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

38.6%