7.5
CVSSv3

CVE-2018-1000632

Published: 20/08/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dom4j project dom4j

debian debian linux 8.0

oracle flexcube investor servicing 12.3.0

oracle flexcube investor servicing 12.1.0

oracle flexcube investor servicing 12.0.4

oracle retail integration bus 15.0

oracle utilities framework 4.2.0.3.0

oracle utilities framework 4.2.0.2.0

oracle flexcube investor servicing 12.4.0

oracle flexcube investor servicing 14.0.0

oracle retail integration bus 16.0

oracle utilities framework 4.4.0.0.0

oracle primavera p6 enterprise project portfolio management

oracle rapid planning 12.1

oracle rapid planning 12.2

oracle utilities framework 4.4.0.2

oracle utilities framework 2.2.0

oracle utilities framework

redhat satellite capsule 6.6

redhat satellite 6.6

redhat jboss_enterprise_application_platform 6.0.0

redhat jboss_enterprise_application_platform 6.4.0

redhat jboss_enterprise_application_platform 7.1.0

netapp snap creator framework -

netapp snapcenter -

netapp snapmanager -

netapp oncommand workflow automation -

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 716 for RHEL 7 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 71 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 716 on RHEL 6 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 71 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as h ...
Synopsis Moderate: Red Hat Satellite 6 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Satellite 66 for RHEL 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scor ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 716 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 71Red Hat Product Security has rated this update as having a security impact of Moderate A Co ...
Synopsis Moderate: Red Hat Single Sign-On 726 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 72 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerab ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 6422 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 64 for Red Hat Enterprise Linux 5Red Hat Product Security has rated this update as having a s ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 6422 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 64 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a s ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 6422 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 64 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a s ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 6422 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 64Red Hat Product Security has rated this update as having a security impact of Moderate A C ...
Synopsis Important: Red Hat Fuse 770 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 76 to 77) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Produc ...

References

CWE-91https://ihacktoprotect.com/post/dom4j-xml-injection/https://github.com/dom4j/dom4j/issues/48https://github.com/dom4j/dom4j/commit/e598eb43d418744c4dbf62f647dd2381c9ce9387https://lists.debian.org/debian-lts-announce/2018/09/msg00028.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://access.redhat.com/errata/RHSA-2019:0365https://access.redhat.com/errata/RHSA-2019:0364https://access.redhat.com/errata/RHSA-2019:0362https://access.redhat.com/errata/RHSA-2019:0380https://access.redhat.com/errata/RHSA-2019:1162https://access.redhat.com/errata/RHSA-2019:1161https://access.redhat.com/errata/RHSA-2019:1160https://access.redhat.com/errata/RHSA-2019:1159https://security.netapp.com/advisory/ntap-20190530-0001/https://access.redhat.com/errata/RHSA-2019:3172https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3Ehttps://lists.apache.org/thread.html/7f6e120e6ed473f4e00dde4c398fc6698eb383bd7857d20513e989ce%40%3Cdev.maven.apache.org%3Ehttps://lists.apache.org/thread.html/4a77652531d62299a30815cf5f233af183425db8e3c9a824a814e768%40%3Cdev.maven.apache.org%3Ehttps://lists.apache.org/thread.html/5a020ecaa3c701f408f612f7ba2ee37a021644c4a39da2079ed3ddbc%40%3Ccommits.maven.apache.org%3Ehttps://lists.apache.org/thread.html/00571f362a7a2470fba50a31282c65637c40d2e21ebe6ee535a4ed74%40%3Ccommits.maven.apache.org%3Ehttps://lists.apache.org/thread.html/d7d960b2778e35ec9b4d40c8efd468c7ce7163bcf6489b633491c89f%40%3Cdev.maven.apache.org%3Ehttps://lists.apache.org/thread.html/9d4c1af6f702c3d6d6f229de57112ddccac8ce44446a01b7937ab9e0%40%3Ccommits.maven.apache.org%3Ehttps://lists.apache.org/thread.html/7e9e78f0e4288fac6591992836d2a80d4df19161e54bd71ab4b8e458%40%3Cdev.maven.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IOOVVCRQE6ATFD2JM2EMDXOQXTRIVZGP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJULAHVR3I5SX7OSMXAG75IMNSAYOXGA/https://lists.apache.org/thread.html/rb1b990d7920ae0d50da5109b73b92bab736d46c9788dd4b135cb1a51%40%3Cnotifications.freemarker.apache.org%3Ehttps://nvd.nist.govhttps://access.redhat.com/errata/RHSA-2019:0365