PT-2019-15280 · Red Hat · Xml Language Server+1

Published

2019-10-23

·

Updated

2021-07-21

·

CVE-2019-18213

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XML Language Server versions prior to 0.9.1 Red Hat XML Language Support versions prior to 0.9.1
Description The issue allows for XXE (XML External Entity) attacks via a crafted XML document. This can result in SSRF (Server-Side Request Forgery) and the initiation of SMB connections, potentially leading to the capture of NetNTLM challenge/response for password cracking.
Recommendations For XML Language Server versions prior to 0.9.1, update to version 0.9.1 or later. For Red Hat XML Language Support versions prior to 0.9.1, update to version 0.9.1 or later.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18213

Affected Products

Red Hat Xml Language Support
Xml Language Server