Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7001
HistoryJul 10, 2018 - 5:40 a.m.

XML External Entity (XXE) Injection

2018-07-1005:40:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.003

Percentile

71.6%

Onos Controller is vulnerable to XML external entitiy (XXE) injection attack. It is possible because the application does not disable Document Type Definition (DTD) External Entities by default, allowing a malicious user to inject malicious external entities through XML files.

EPSS

0.003

Percentile

71.6%

Related for VERACODE:7001