CVE-2015-1832
ADVISORY - githubSummary
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
EPSS Score: 0.12173 (0.956)
Common Weakness Enumeration (CWE)
ADVISORY - nist
ADVISORY - github
Improper Restriction of XML External Entity Reference
ADVISORY - gitlab
ADVISORY - redhat
Improper Restriction of XML External Entity Reference
NIST
CVSS SCORE
9.1criticalGitHub
CREATED
UPDATED
ADVISORY IDGHSA-wr69-g62g-2r9h
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
9.1criticalDebian
CREATED
UPDATED
ADVISORY IDCVE-2015-1832
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2015-1832
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
9.1mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2015-1832
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)