5
CVSSv2

CVE-2016-3674

Published: 17/05/2016 Updated: 26/03/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream prior to 1.4.9 allow remote malicious users to read arbitrary files via a crafted XML document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

fedoraproject fedora 22

fedoraproject fedora 23

xstream project xstream

Vendor Advisories

Debian Bug report logs - #819455 libxstream-java: CVE-2016-3674: XXE vulnerability Package: src:libxstream-java; Maintainer for src:libxstream-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 28 Mar 2016 18:48:02 UTC Sever ...
It was discovered that XStream, a Java library to serialize objects to XML and back again, was susceptible to XML External Entity attacks For the stable distribution (jessie), this problem has been fixed in version 147-2+deb8u1 For the testing distribution (stretch), this problem has been fixed in version 149-1 For the unstable distribution ...
It was found that several XML parsers used by XStream had default settings that would expand entity references A remote, unauthenticated attacker could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks ...