XML External Entity injection in Apache FOP - CVE-2024-28168

 

XML External Entity injection in Apache FOP - CVE-2024-28168

Published: October 14, 2024


Vulnerability identifier: #VU98498
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-28168
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

Apache FOP
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Oracle Financial Services Revenue Management and Billing
Oracle Communications MetaSolv Solution
Dell EMC VxRail Appliance
Oracle Financial Services Analytical Applications Infrastructure
Oracle Communications Policy Management
Oracle Banking Digital Experience
Infrastructure Technology
Oracle Banking APIs
Oracle Communications EAGLE Element Management System
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM InfoSphere Information Server
Oracle Business Process Management Suite
Added support for font-selection-strategy=character
xmlgraphics-batik-css
xmlgraphics-batik-slideshow
xmlgraphics-batik-demo
xmlgraphics-batik-rasterizer
xmlgraphics-batik
xmlgraphics-batik-squiggle
xmlgraphics-batik-ttf2svg
xmlgraphics-batik-javadoc
xmlgraphics-batik-svgpp
fop
xmlgraphics-commons-javadoc
xmlgraphics-commons
xmlgraphics-fop
javapackages-tools
javapackages-filesystem
javapackages-local
javapackages-ivy
javapackages-gradle
python3-javapackages
Planning Analytics Local
IBM Cognos Controller
Cloud Tiering Appliance

How to mitigate CVE-2024-28168

Install updates from vendor's website.

Apache FOP - update to 2.10
Dell EMC VxRail Appliance - addressed in versions 7.0.533, 8.320, 8.321
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
Added support for font-selection-strategy=character - update to by-character
xmlgraphics-batik-css - update to 1.18-150200.4.10.2
xmlgraphics-batik-slideshow - update to 1.18-150200.4.10.2
xmlgraphics-batik-demo - update to 1.18-150200.4.10.2
xmlgraphics-batik-rasterizer - update to 1.18-150200.4.10.2
xmlgraphics-batik - update to 1.18-150200.4.10.2
xmlgraphics-batik-squiggle - update to 1.18-150200.4.10.2
xmlgraphics-batik-ttf2svg - update to 1.18-150200.4.10.2
xmlgraphics-batik-javadoc - update to 1.18-150200.4.10.2
xmlgraphics-batik-svgpp - update to 1.18-150200.4.10.2
Planning Analytics Local - addressed in versions 2.0.0.101, 2.1.8
fop - update to 2.2-7
xmlgraphics-commons-javadoc - update to 2.10-150200.3.10.2
xmlgraphics-commons - update to 2.10-150200.3.10.2
xmlgraphics-fop - update to 2.10-150200.13.10.1
javapackages-tools - update to 6.3.4-150200.3.15.1
javapackages-filesystem - update to 6.3.4-150200.3.15.1
javapackages-local - update to 6.3.4-150200.3.15.1
javapackages-ivy - update to 6.3.4-150200.3.15.1
javapackages-gradle - update to 6.3.4-150200.3.15.1
python3-javapackages - update to 6.3.4-150200.3.15.1
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
Cloud Tiering Appliance - update to 13.2.0.2.33
IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins