XXE attack in Unified Data Protection - #VU15521
Published: October 25, 2018
Unified Data Protection
Detailed vulnerability description
The vulnerability exists in the Web Services components of the UDP Console and UDP Gateway due to an error when parsing a malicious XML file containing a reference to an external entity. A remote attacker can supply a specially crafted XML file and gain access to potentially sensitive information via /management/UdpHttpService.