CVE-2017-18197
UnknownEPSS 3.00%
Last modified
CVE-2017-18197 is a vulnerability of currently unknown severity. In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.. EPSS estimates a 3.00% chance of exploitation in the next 30 days.
Description
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jgraph | Mxgraph | <= 3.7.5 |
References
- https://github.com/jgraph/mxgraph/issues/124Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00002.htmlThird Party Advisory
- https://github.com/jgraph/mxgraph/issues/124Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00002.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-18197?
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
How severe is CVE-2017-18197?
Severity scoring for CVE-2017-18197 is pending analysis. The EPSS model estimates a 3.00% probability of exploitation in the next 30 days.
How do I fix CVE-2017-18197?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-18191An issue was discovered in OpenStack Nova 15.x through 15.1.…
- CVE-2017-18192smart/calculator/gallerylock/CalculatorActivity.java in the …
- CVE-2017-18193fs/f2fs/extent_cache.c in the Linux kernel before 4.13 misha…
- CVE-2017-18194SQL injection vulnerability in users/signup.php in the "sign…
- CVE-2017-18195An issue was discovered in tools/conversations/view_ajax.php…5.3
- CVE-2017-18196Leptonica 1.74.4 constructs unintended pathnames (containing…
- CVE-2017-18198print_iso9660_recurse in iso-info.c in GNU libcdio before 1.…
- CVE-2017-18199realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows…
- CVE-2017-1820Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-18200The f2fs implementation in the Linux kernel before 4.14 mish…
- CVE-2017-18201An issue was discovered in GNU libcdio before 2.0.0. There i…
- CVE-2017-18202The __oom_reap_task_mm function in mm/oom_kill.c in the Linu…7
Are you affected by CVE-2017-18197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
