PT-2024-9589 · Ucum-Java · Ucum-Java

Dotasek

·

Published

2024-12-13

·

Updated

2024-12-13

·

CVE-2024-55887

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ucum-java versions prior to 1.0.9
Description The issue is related to XML external entity injections in the UcumEssenceService. This occurs when XML parsing is performed, allowing a malicious DTD tag in a processed XML file to produce XML containing data from the host system. This impacts scenarios where Ucum-java is used within a host and external clients can submit XML.
Recommendations For versions prior to 1.0.9, update to release 1.0.9 to fix the vulnerability. As a temporary workaround, ensure that the source XML for instantiating UcumEssenceService is trusted.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2024-11297
CVE-2024-55887
GHSA-W9J7-PHM3-F97J

Affected Products

Ucum-Java