PT-2016-3245 · Apache · Apache Xml-Rpc Library
0Ang3El
·
Publicado
2016-07-12
·
Atualizado
2024-01-22
·
CVE-2016-5002
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache XML-RPC library version 3.1.3
Description
The issue is related to an XML external entity (XXE) vulnerability in the Apache XML-RPC library. This vulnerability allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD. The vulnerability is caused by incorrect restriction of XML links to external objects.
Recommendations
For Apache XML-RPC library version 3.1.3, consider disabling the XML external entity processing to prevent SSRF attacks until a patch is available. Restrict access to the library to minimize the risk of exploitation. Avoid using crafted DTDs in the affected library until the issue is resolved.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Xml-Rpc Library