Описание
An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versions are also affected. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.2 (включая)
cpe:2.3:a:apache:soap:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00135
Низкий
7.5 High
CVSS3
Дефекты
CWE-611
CWE-611
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Apache SOAP's RPCRouterServlet allows reading of arbitrary files over HTTP
EPSS
Процентиль: 34%
0.00135
Низкий
7.5 High
CVSS3
Дефекты
CWE-611
CWE-611