Описание
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
Уязвимые конфигурации
Конфигурация 1Версия до 11.1.0.6 (исключая)Версия от 12.0 (включая) до 12.1.1 (исключая)
Одно из
cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltech:unica:*:*:*:*:*:*:*:*
EPSS
Процентиль: 33%
0.00128
Низкий
8.1 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 8.1
github
больше 2 лет назад
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights can successfully perform XML External Entity attacks (XXE) against the backend service.
EPSS
Процентиль: 33%
0.00128
Низкий
8.1 High
CVSS3
8.8 High
CVSS3
Дефекты
CWE-611