Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41312
HistoryJul 17, 2023 - 9:10 a.m.

XML External Entity (XXE) Attacks

2023-07-1709:10:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
xml parser
xxe attacks
crafted http request

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

21.3%

External Monitor Job Type Plugin is vulnerable to XML External Entity (XXE) Attacks. The vulnerability exists because it does not properly configure the XML parser which allows an attacker with Item/Build permission to parse a crafted HTTP request with XML data, resulting in external entity (XXE) attacks.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

21.3%