XXE attack in dom4j - CVE-2018-1000632

 

XXE attack in dom4j - CVE-2018-1000632

Published: August 21, 2018 / Updated: August 23, 2018


Vulnerability identifier: #VU14515
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000632
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct XXE attack on the target system.

The vulnerability exists due to improper sanitization of elements and attribute names in XML documents. A remote attacker can trick the victim into opening a specially crafted XML document that submits malicious input, perform XXE attack and bypass security restrictions to access and modify sensitive information on the system.


Affected software

dom4j
Oracle Utilities Framework
IBM Business Automation Manager Open Editions
Oracle FLEXCUBE Investor Servicing
CloudLink
IBM Cloud Pak System
Red Hat Virtualization Host
Red Hat Virtualization
IBM Intelligent Operations Center
IBM Spectrum Control
Atlas eDiscovery Process Management
Tivoli Composite Application Manager for Transactions
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
SPSS Statistics
IBM Qradar SIEM
Opensuse
Ubuntu
Fedora
libdom4j-java (Ubuntu package)
dom4j
rhvm-appliance (Red Hat package)
IBM TRIRIGA Application Platform

How to mitigate CVE-2018-1000632

Update to version 2.1.1.

dom4j - update to 2.1.1
IBM Cloud Pak System - update to 2.3.3.6
IBM Intelligent Operations Center - update to 5.2.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
IBM Business Automation Manager Open Editions - update to 8.0.8
libdom4j-java (Ubuntu package) - update to 1.6.1+dfsg.3-2ubuntu1.2
dom4j - addressed in versions 2.0.3-1.fc33, 2.0.3-1.fc34
IBM TRIRIGA Application Platform - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
rhvm-appliance (Red Hat package) - update to 4.3-20190502.0.el7
IBM Spectrum Control - update to 5.4.10
Atlas eDiscovery Process Management - update to 6.0.3.9.7
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.22
CloudLink - update to 8.0-3.10.5.1
IBM Security Verify Governance - update to 10.0.1.0.2
IBM Business Automation Workflow - addressed in versions 21.0.3 IF028, 23.0.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
SPSS Statistics - update to 29.0

External References

Related Security Bulletins