356
VMScore

CVE-2017-15691

Published: 26/04/2018 Updated: 19/06/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In Apache uimaj before 2.10.2, Apache uimaj 3.0.0-xxx before 3.0.0-beta, Apache uima-as before 2.10.2, Apache uimaFIT before 2.4.0, Apache uimaDUCC before 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA as part of its configuration and operation may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.

Vulnerable Product Search on Vulmon Subscribe to Product

apache uimaj

apache uimaj 3.0.0

apache uima-as

apache uimafit

apache uimaducc

Vendor Advisories

Synopsis Important: Red Hat Fuse 731 security update Type/Severity Security Advisory: Important Topic A micro version update (from 73 to 731) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security ...
Debian Bug report logs - #897009 uimaj: CVE-2017-15691: XML external entity expansion (XXE) attack exposure Package: src:uimaj; Maintainer for src:uimaj is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 27 Apr 2018 04:09:01 UTC ...
In Apache uimaj prior to 2102, Apache uimaj 300-xxx prior to 300-beta, Apache uima-as prior to 2102, Apache uimaFIT prior to 240, Apache uimaDUCC prior to 222, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers UIMA as part of its configuration and operation may read XML from various ...