PT-2018-9991 · Sel · Acselerator Architect
Publicado
2018-07-24
·
Atualizado
2019-10-09
·
CVE-2018-10600
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SEL AcSELerator Architect versions 2.2.24.0 and prior
Description:
The issue allows unsanitized input to be passed to the XML parser, which may lead to disclosure and retrieval of arbitrary data, arbitrary code execution in certain situations on specific platforms, and denial of service attacks.
Recommendations:
For SEL AcSELerator Architect versions 2.2.24.0 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Acselerator Architect