XXE attack in Apache Oozie - CVE-2017-15712
Published: February 19, 2018 / Updated: February 19, 2018
Vulnerability identifier: #VU10632
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15712
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform XXE attack.
The weakness exists due to constructing a workflow XML file containing XML directives. A remote attacker can obtain private files on the server process.
Affected software
Apache Oozie
Cloudera Data Platform Private Cloud Base for IBM
Cloudera Data Platform Private Cloud Base for IBM
How to mitigate CVE-2017-15712
Update to version 4.3.1 or later.
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.3 HF2