Логотип exploitDog
bind:CVE-2019-11216
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-11216

Количество 2

Количество 2

nvd логотип

CVE-2019-11216

около 6 лет назад

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pf85-6vfc-9453

больше 3 лет назад

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-11216

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
github логотип
GHSA-pf85-6vfc-9453

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу