icon

We found results for “

WS-2019-0612

Good to know:

icon

Date: November 14, 2019

In Axelor Open-Suite, versions v5.0.0-rc1 through v5.1.11 are vulnerable to XML External Entity Reference (XXE), due to XXE processing not disabled when parsing a BPM workflow file. A privileged attacker can upload a specially crafted XML file and trigger DoS and in some cases even RCE.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Improper Restriction of XML External Entity Reference ('XXE')

CWE-611

Top Fix

icon

Upgrade Version

Upgrade to version v5.1.12

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us