CVE-2018-6486
MFSBGN03797 rev.1 - Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), XML External Entity Injection
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.
Vulnerabilidad XEE (XML External Entity) en Micro Focus Fortify Audit Workbench (AWB) y Micro Focus Fortify Software Security Center (SSC), versiones 16.10, 16.20 y 17.10. Esta vulnerabilidad podría ser explotada para permitir inyección XEE (XML External Entity).
*Credits:
Micro Focus would like to thank Jakub Palaczynski for reporting this issue to security-alert@hpe.com
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-02-01 CVE Reserved
- 2018-02-02 CVE Published
- 2023-11-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102902 | Vdb Entry | |
https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03083653 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microfocus Search vendor "Microfocus" | Fortify Audit Workbench Search vendor "Microfocus" for product "Fortify Audit Workbench" | 16.10 Search vendor "Microfocus" for product "Fortify Audit Workbench" and version "16.10" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Fortify Audit Workbench Search vendor "Microfocus" for product "Fortify Audit Workbench" | 16.20 Search vendor "Microfocus" for product "Fortify Audit Workbench" and version "16.20" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Fortify Audit Workbench Search vendor "Microfocus" for product "Fortify Audit Workbench" | 17.10 Search vendor "Microfocus" for product "Fortify Audit Workbench" and version "17.10" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Fortify Software Security Center Search vendor "Microfocus" for product "Fortify Software Security Center" | 16.10 Search vendor "Microfocus" for product "Fortify Software Security Center" and version "16.10" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Fortify Software Security Center Search vendor "Microfocus" for product "Fortify Software Security Center" | 16.20 Search vendor "Microfocus" for product "Fortify Software Security Center" and version "16.20" | - |
Affected
| ||||||
Microfocus Search vendor "Microfocus" | Fortify Software Security Center Search vendor "Microfocus" for product "Fortify Software Security Center" | 17.10 Search vendor "Microfocus" for product "Fortify Software Security Center" and version "17.10" | - |
Affected
|