Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7005
HistoryJul 10, 2018 - 9:39 a.m.

XML External Entity (XXE) Injection

2018-07-1009:39:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.006

Percentile

78.9%

onos-drivers-utilities is vulnerable to XML external entitiy (XXE) injection attacks. The application does not disable document type declarations (DTD), allowing a malicious user can inject external entities through the loadxml() function in XmlConfigParser.java.

EPSS

0.006

Percentile

78.9%

Related for VERACODE:7005