PT-2016-3245 · Apache · Apache Xml-Rpc Library

0Ang3El

·

Published

2016-07-12

·

Updated

2024-01-22

·

CVE-2016-5002

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache XML-RPC library version 3.1.3
Description The issue is related to an XML external entity (XXE) vulnerability in the Apache XML-RPC library. This vulnerability allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD. The vulnerability is caused by incorrect restriction of XML links to external objects.
Recommendations For Apache XML-RPC library version 3.1.3, consider disabling the XML external entity processing to prevent SSRF attacks until a patch is available. Restrict access to the library to minimize the risk of exploitation. Avoid using crafted DTDs in the affected library until the issue is resolved.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2018-00149
CVE-2016-5002
GHSA-WP35-6JQV-R33M
MGASA-2019-0002

Affected Products

Apache Xml-Rpc Library