CVE-2018-12243
Last modified
CVE-2018-12243 is a vulnerability of currently unknown severity. The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Messaging Gateway | < 10.6.6 |
References
- http://www.securityfocus.com/bid/105330Third Party Advisory, VDB Entry
- https://support.symantec.com/en_US/article.SYMSA1461.htmlMitigation, Vendor Advisory
- http://www.securityfocus.com/bid/105330Third Party Advisory, VDB Entry
- https://support.symantec.com/en_US/article.SYMSA1461.htmlMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12243?
How severe is CVE-2018-12243?
How do I fix CVE-2018-12243?
Are you affected by CVE-2018-12243?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
