Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-0581

Опубликовано: 28 янв. 2015
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:prime_service_catalog:*:*:*:*:*:*:*:*
Версия до 10.0 (включая)

EPSS

Процентиль: 65%
0.0048
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.

EPSS

Процентиль: 65%
0.0048
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other