Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ph8x-8q5q-f3mh

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.

EPSS

Процентиль: 41%
0.00192
Низкий

8 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8
nvd
почти 8 лет назад

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.

EPSS

Процентиль: 41%
0.00192
Низкий

8 High

CVSS3

Дефекты

CWE-611