PT-2016-3245 · Apache · Apache Xml-Rpc Library

0Ang3El

·

Publicado

2016-07-12

·

Atualizado

2024-01-22

·

CVE-2016-5002

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache XML-RPC library version 3.1.3
Description The issue is related to an XML external entity (XXE) vulnerability in the Apache XML-RPC library. This vulnerability allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD. The vulnerability is caused by incorrect restriction of XML links to external objects.
Recommendations For Apache XML-RPC library version 3.1.3, consider disabling the XML external entity processing to prevent SSRF attacks until a patch is available. Restrict access to the library to minimize the risk of exploitation. Avoid using crafted DTDs in the affected library until the issue is resolved.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00149
CVE-2016-5002
GHSA-WP35-6JQV-R33M
MGASA-2019-0002

Produtos afetados

Apache Xml-Rpc Library