PT-2020-7623 · Hewlett Packard · Hp Fortify Sca

Published

2020-02-19

·

Updated

2020-03-06

·

CVE-2014-2228

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HP Fortify SCA versions prior to 2.2 RC3
Description The issue allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages. This is related to the XStream extension in HP Fortify SCA.
Recommendations For versions prior to 2.2 RC3, update to version 2.2 RC3 or later to resolve the issue. As a temporary workaround, consider restricting access to the XStream extension to minimize the risk of exploitation.

Exploit

Fix

XML Entity Expansion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2228

Affected Products

Hp Fortify Sca