CVE-2017-15691

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA as part of its configuration and operation may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
apacheuimaj
𝑥
< 2.10.2
apacheuimaj
3.0.0
apacheuimaj
3.0.0:alpha
apacheuimaj
3.0.0:alpha2
apacheuima-as
𝑥
< 2.10.2
apacheuimafit
𝑥
< 2.4.0
apacheuimaducc
𝑥
< 2.2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
uimaj
sid
2.10.2-4
fixed
trixie
2.10.2-4
fixed
bookworm
2.10.2-4
fixed
bullseye
2.10.2-4
fixed
stretch
no-dsa
jessie
no-dsa
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
uimaj
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
ignored
bionic
needed
artful
ignored
xenial
needed
trusty
dne