CVE-2018-1000632

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
dom4j_projectdom4j
2.0.0 ≤
𝑥
< 2.0.3
dom4j_projectdom4j
2.1.0 ≤
𝑥
< 2.1.1
debiandebian_linux
8.0
oracleflexcube_investor_servicing
12.0.4
oracleflexcube_investor_servicing
12.1.0
oracleflexcube_investor_servicing
12.3.0
oracleflexcube_investor_servicing
12.4.0
oracleflexcube_investor_servicing
14.0.0
oracleprimavera_p6_enterprise_project_portfolio_management
16.1.0.0 ≤
𝑥
≤ 16.2.20.1
oracleprimavera_p6_enterprise_project_portfolio_management
17.1.0.0 ≤
𝑥
≤ 17.12.17.1
oracleprimavera_p6_enterprise_project_portfolio_management
18.1.0.0 ≤
𝑥
≤ 18.8.19.0
oracleprimavera_p6_enterprise_project_portfolio_management
19.12.0.0 ≤
𝑥
≤ 19.12.6.0
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oracleretail_integration_bus
15.0
oracleretail_integration_bus
16.0
oracleutilities_framework
4.3.0.2.0 ≤
𝑥
≤ 4.3.0.6.0
oracleutilities_framework
2.2.0
oracleutilities_framework
4.2.0.2.0
oracleutilities_framework
4.2.0.3.0
oracleutilities_framework
4.4.0.0.0
oracleutilities_framework
4.4.0.2
redhatsatellite
6.6
redhatsatellite_capsule
6.6
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
redhatjboss_enterprise_application_platform
7.1.0
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
netapponcommand_workflow_automation
-
netappsnap_creator_framework
-
netappsnapcenter
-
netappsnapmanager
-
netappsnapmanager
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dom4j
bullseye
2.1.3-1
fixed
bookworm
2.1.3-2
fixed
sid
2.1.4-1
fixed
trixie
2.1.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dom4j
noble
Fixed 2.1.1-1
released
mantic
Fixed 2.1.1-1
released
lunar
Fixed 2.1.1-1
released
kinetic
Fixed 2.1.1-1
released
jammy
Fixed 2.1.1-1
released
impish
Fixed 2.1.1-1
released
hirsute
Fixed 2.1.1-1
released
groovy
Fixed 2.1.1-1
released
focal
Fixed 2.1.1-1
released
eoan
Fixed 2.1.1-1
released
disco
Fixed 2.1.1-1
released
cosmic
Fixed 2.1.1-1
released
bionic
needed
xenial
Fixed 1.6.1+dfsg.3-2ubuntu1.2
released
trusty
needs-triage
References