CVE-2018-1000632

EUVD-2018-0521
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
aka Blind XPath Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
dom4j_projectdom4j
2.0.0 ≤
𝑥
< 2.0.3
dom4j_projectdom4j
2.1.0 ≤
𝑥
< 2.1.1
debiandebian_linux
8.0
oracleflexcube_investor_servicing
12.0.4
oracleflexcube_investor_servicing
12.1.0
oracleflexcube_investor_servicing
12.3.0
oracleflexcube_investor_servicing
12.4.0
oracleflexcube_investor_servicing
14.0.0
oracleprimavera_p6_enterprise_project_portfolio_management
16.1.0.0 ≤
𝑥
≤ 16.2.20.1
oracleprimavera_p6_enterprise_project_portfolio_management
17.1.0.0 ≤
𝑥
≤ 17.12.17.1
oracleprimavera_p6_enterprise_project_portfolio_management
18.1.0.0 ≤
𝑥
≤ 18.8.19.0
oracleprimavera_p6_enterprise_project_portfolio_management
19.12.0.0 ≤
𝑥
≤ 19.12.6.0
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oracleretail_integration_bus
15.0
oracleretail_integration_bus
16.0
oracleutilities_framework
4.3.0.2.0 ≤
𝑥
≤ 4.3.0.6.0
oracleutilities_framework
2.2.0
oracleutilities_framework
4.2.0.2.0
oracleutilities_framework
4.2.0.3.0
oracleutilities_framework
4.4.0.0.0
oracleutilities_framework
4.4.0.2
redhatsatellite
6.6
redhatsatellite_capsule
6.6
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
redhatjboss_enterprise_application_platform
7.1.0
redhatjboss_enterprise_application_platform
6.0.0
redhatjboss_enterprise_application_platform
6.4.0
netapponcommand_workflow_automation
-
netappsnap_creator_framework
-
netappsnapcenter
-
netappsnapmanager
-
netappsnapmanager
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dom4j
bookworm
2.1.3-2
fixed
bullseye
2.1.3-1
fixed
sid
2.1.4-1
fixed
trixie
2.1.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dom4j
bionic
needed
cosmic
Fixed 2.1.1-1
released
disco
Fixed 2.1.1-1
released
eoan
Fixed 2.1.1-1
released
focal
Fixed 2.1.1-1
released
groovy
Fixed 2.1.1-1
released
hirsute
Fixed 2.1.1-1
released
impish
Fixed 2.1.1-1
released
jammy
Fixed 2.1.1-1
released
kinetic
Fixed 2.1.1-1
released
lunar
Fixed 2.1.1-1
released
mantic
Fixed 2.1.1-1
released
noble
Fixed 2.1.1-1
released
trusty
needs-triage
xenial
Fixed 1.6.1+dfsg.3-2ubuntu1.2
released
References