Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8064
HistoryDec 21, 2018 - 9:33 a.m.

XML External Entity Injection (XXE)

2018-12-2109:33:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.002 Low

EPSS

Percentile

53.0%

bw-calendar-engine-impl is vulnerable to XML external entity injection (XXE). The vulnerability exists since the IscheduleClient XML parser does not restrict external DTDs which would allow an attacker to perform XXE attacks via a crafted XML document.

0.002 Low

EPSS

Percentile

53.0%

Related for VERACODE:8064