Vulnerability Description
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Derby | 10.1.1.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21990100Third Party Advisory
- http://www.securityfocus.com/bid/93132Third Party AdvisoryVDB Entry
- https://issues.apache.org/jira/browse/DERBY-6807Issue Tracking
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c24
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12e
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d28
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133dee
- https://svn.apache.org/viewvc?view=revision&revision=1691461Issue Tracking
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- http://www-01.ibm.com/support/docview.wss?uid=swg21990100Third Party Advisory
- http://www.securityfocus.com/bid/93132Third Party AdvisoryVDB Entry
FAQ
What is CVE-2015-1832?
CVE-2015-1832 is a vulnerability with a CVSS score of 9.1 (CRITICAL). XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary file...
How severe is CVE-2015-1832?
CVE-2015-1832 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-1832?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Derby.