PT-2016-3245 · Apache · Apache Xml-Rpc Library
0Ang3El
·
Published
2016-07-12
·
Updated
2024-01-22
·
CVE-2016-5002
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache XML-RPC library version 3.1.3
Description
The issue is related to an XML external entity (XXE) vulnerability in the Apache XML-RPC library. This vulnerability allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD. The vulnerability is caused by incorrect restriction of XML links to external objects.
Recommendations
For Apache XML-RPC library version 3.1.3, consider disabling the XML external entity processing to prevent SSRF attacks until a patch is available. Restrict access to the library to minimize the risk of exploitation. Avoid using crafted DTDs in the affected library until the issue is resolved.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Xml-Rpc Library