CVE-2018-1000632

HIGHCVSS 7.5/10EPSS 6.57%

Last modified

CVE-2018-1000632 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. EPSS estimates a 6.57% chance of exploitation in the next 30 days.

Description

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
6.57%

93.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Dom4j ProjectDom4j>= 2.0.0, < 2.0.3
Dom4j ProjectDom4j>= 2.1.0, < 2.1.1
DebianDebian Linux8.0
OracleFlexcube Investor Servicing12.0.4
OracleFlexcube Investor Servicing12.1.0
OracleFlexcube Investor Servicing12.3.0
OracleFlexcube Investor Servicing12.4.0
OracleFlexcube Investor Servicing14.0.0
OraclePrimavera P6 Enterprise Project Portfolio Management>= 16.1.0.0, <= 16.2.20.1
OraclePrimavera P6 Enterprise Project Portfolio Management>= 17.1.0.0, <= 17.12.17.1
OraclePrimavera P6 Enterprise Project Portfolio Management>= 18.1.0.0, <= 18.8.19.0
OraclePrimavera P6 Enterprise Project Portfolio Management>= 19.12.0.0, <= 19.12.6.0
OracleRapid Planning12.1
OracleRapid Planning12.2
OracleRetail Integration Bus15.0
OracleRetail Integration Bus16.0
OracleUtilities Framework>= 4.3.0.2.0, <= 4.3.0.6.0
OracleUtilities Framework2.2.0
OracleUtilities Framework4.2.0.2.0
OracleUtilities Framework4.2.0.3.0
OracleUtilities Framework4.4.0.0.0
OracleUtilities Framework4.4.0.2
RedhatSatellite6.6
RedhatSatellite Capsule6.6
RedhatJboss Enterprise Application Platform6.0.0
RedhatJboss Enterprise Application Platform6.4.0
RedhatJboss Enterprise Application Platform7.1.0
NetappOncommand Workflow AutomationAll versions
NetappSnap Creator FrameworkAll versions
NetappSnapcenterAll versions
NetappSnapmanagerAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1000632?
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
How severe is CVE-2018-1000632?
CVE-2018-1000632 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 6.57% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1000632?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1000632?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST