PT-2018-9991 · Sel · Acselerator Architect
Published
2018-07-24
·
Updated
2019-10-09
·
CVE-2018-10600
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SEL AcSELerator Architect versions 2.2.24.0 and prior
Description:
The issue allows unsanitized input to be passed to the XML parser, which may lead to disclosure and retrieval of arbitrary data, arbitrary code execution in certain situations on specific platforms, and denial of service attacks.
Recommendations:
For SEL AcSELerator Architect versions 2.2.24.0 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acselerator Architect