SB2018061415 - XML External Entity injection in WebCTRL



SB2018061415 - XML External Entity injection in WebCTRL

Published: June 14, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018061415
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) XML External Entity injection (CVE-ID: CVE-2018-8819)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.


Remediation

Install update from vendor's website.