HIGH · 7.5

CVE-2018-1000632

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents thr...

Vulnerability Description

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
Dom4J ProjectDom4J>= 2.0.0, < 2.0.3
DebianDebian Linux8.0
OracleFlexcube Investor Servicing12.0.4
OraclePrimavera P6 Enterprise Project Portfolio Management>= 16.1.0.0, <= 16.2.20.1
OracleRapid Planning12.1
OracleRetail Integration Bus15.0
OracleUtilities Framework>= 4.3.0.2.0, <= 4.3.0.6.0
RedhatSatellite6.6
RedhatSatellite Capsule6.6
RedhatJboss Enterprise Application Platform6.0.0
RedhatEnterprise Linux6.0
NetappOncommand Workflow Automation-
NetappSnap Creator Framework-
NetappSnapcenter-
NetappSnapmanager-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-1000632?

CVE-2018-1000632 is a vulnerability with a CVSS score of 7.5 (HIGH). dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents thr...

How severe is CVE-2018-1000632?

CVE-2018-1000632 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-1000632?

Check the references section above for vendor advisories and patch information. Affected products include: Dom4J Project Dom4J, Debian Debian Linux, Oracle Flexcube Investor Servicing, Oracle Primavera P6 Enterprise Project Portfolio Management, Oracle Rapid Planning.