7.5
CVSSv2

CVE-2018-15531

Published: 26/09/2018 Updated: 29/11/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

JavaMelody prior to 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

javamelody project javamelody

Github Repositories

Jenkins monitoring plugin

Monitoring plugin Monitoring plugin: Monitoring of the performance of Jenkins itself with JavaMelody Open the report (or yourhost/monitoring) after installation Author : Emeric Vernat (evernat at freefr) License ASL Features summarized Charts of memory, cpu, system load average, http response times by day, week, month, year or custom period Statistics of http req