Lucene search

K
nvd[email protected]NVD:CVE-2013-6440
HistoryFeb 14, 2014 - 3:55 p.m.

CVE-2013-6440

2014-02-1415:55:05
CWE-200
web.nvd.nist.gov
8

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

67.8%

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.

Affected configurations

Nvd
Node
internet2opensamlMatch2.0
OR
internet2opensamlMatch2.1.0
OR
internet2opensamlMatch2.2.0
OR
shibbolethopensamlRange2.6.0
OR
shibbolethopensamlMatch2.4.0
OR
shibbolethopensamlMatch2.4.1
OR
shibbolethopensamlMatch2.4.2
OR
shibbolethopensamlMatch2.4.3
OR
shibbolethopensamlMatch2.5.0
OR
shibbolethopensamlMatch2.5.1
OR
shibbolethopensamlMatch2.5.2
OR
shibbolethopensamlMatch2.5.3
VendorProductVersionCPE
internet2opensaml2.0cpe:2.3:a:internet2:opensaml:2.0:*:*:*:*:*:*:*
internet2opensaml2.1.0cpe:2.3:a:internet2:opensaml:2.1.0:*:*:*:*:*:*:*
internet2opensaml2.2.0cpe:2.3:a:internet2:opensaml:2.2.0:*:*:*:*:*:*:*
shibbolethopensaml*cpe:2.3:a:shibboleth:opensaml:*:*:*:*:*:*:*:*
shibbolethopensaml2.4.0cpe:2.3:a:shibboleth:opensaml:2.4.0:*:*:*:*:*:*:*
shibbolethopensaml2.4.1cpe:2.3:a:shibboleth:opensaml:2.4.1:*:*:*:*:*:*:*
shibbolethopensaml2.4.2cpe:2.3:a:shibboleth:opensaml:2.4.2:*:*:*:*:*:*:*
shibbolethopensaml2.4.3cpe:2.3:a:shibboleth:opensaml:2.4.3:*:*:*:*:*:*:*
shibbolethopensaml2.5.0cpe:2.3:a:shibboleth:opensaml:2.5.0:*:*:*:*:*:*:*
shibbolethopensaml2.5.1cpe:2.3:a:shibboleth:opensaml:2.5.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

67.8%