XML External Entity injection in Artemis - CVE-2015-3208
Published: July 19, 2019
Artemis
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input when the XPath selector component allows use of External Entities. A remote attacker can pass a specially crafted XML code to the affected application and have unspecified impact via unknown vectors.