Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-3208
HistoryJun 11, 2018 - 5:29 p.m.

Design/Logic Flaw

2018-06-1117:29:00
PRIOn knowledge base
www.prio-n.com
4

9.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.5%

The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data on the server, denial of service, or server side request forgery.

CPENameOperatorVersion
weborb_for_javaeq5.1.1.0

9.5 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.5%

Related for PRION:CVE-2017-3208