XXE attack in Apache Derby - CVE-2015-1832
Published: October 4, 2016 / Updated: March 21, 2018
Vulnerability identifier: #VU735
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-1832
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to conduct XXE attack.
The weakness exists due to XML external entity error. Via vectors involving XmlVTI and the XML datatype context-dependent attackers can view arbitrary files that may lead to denial of service.
Successful exploitation of the vulnerability can result in potentially sensitive information disclosure and denial of service on the vulnerable system.
The weakness exists due to XML external entity error. Via vectors involving XmlVTI and the XML datatype context-dependent attackers can view arbitrary files that may lead to denial of service.
Successful exploitation of the vulnerability can result in potentially sensitive information disclosure and denial of service on the vulnerable system.
Affected software
Apache Derby
IBM Cloud Pak System
Oracle Knowledge
IBM Integration Bus
Netcool Operations Insight
IBM App Connect Enterprise
Oracle WebLogic Server
Primavera Unifier
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Operational Decision Manager
IBM Cloud Pak System
Oracle Knowledge
IBM Integration Bus
Netcool Operations Insight
IBM App Connect Enterprise
Oracle WebLogic Server
Primavera Unifier
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Operational Decision Manager
How to mitigate CVE-2015-1832
Update to 10.12.1.1.
IBM Cloud Pak System - update to 2.3.3.6
Netcool Operations Insight - update to 1.6.12
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
Netcool Operations Insight - update to 1.6.12
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
Operational Decision Manager - addressed in versions 8.11.0.1 Interim fix 32, 8.11.1 Interim fix 25, 8.12.0.1 Interim fix 10
External References
Related Security Bulletins
- XXE attack in Apache Derby
- Multiple vulnerabilities in Oracle Knowledge
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM App Connect Enterprise Toolkit and the IBM Integration Bus Toolkit
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Oracle WebLogic Server