XML External Entity injection in Apache FOP - CVE-2024-28168
Published: October 14, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
Affected software
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Oracle Financial Services Revenue Management and Billing
Oracle Communications MetaSolv Solution
Dell EMC VxRail Appliance
Oracle Financial Services Analytical Applications Infrastructure
Oracle Communications Policy Management
Oracle Banking Digital Experience
Infrastructure Technology
Oracle Banking APIs
Oracle Communications EAGLE Element Management System
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM InfoSphere Information Server
Oracle Business Process Management Suite
Added support for font-selection-strategy=character
xmlgraphics-batik-css
xmlgraphics-batik-slideshow
xmlgraphics-batik-demo
xmlgraphics-batik-rasterizer
xmlgraphics-batik
xmlgraphics-batik-squiggle
xmlgraphics-batik-ttf2svg
xmlgraphics-batik-javadoc
xmlgraphics-batik-svgpp
fop
xmlgraphics-commons-javadoc
xmlgraphics-commons
xmlgraphics-fop
javapackages-tools
javapackages-filesystem
javapackages-local
javapackages-ivy
javapackages-gradle
python3-javapackages
Planning Analytics Local
IBM Cognos Controller
Cloud Tiering Appliance
How to mitigate CVE-2024-28168
Dell EMC VxRail Appliance - addressed in versions 7.0.533, 8.320, 8.321
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
Added support for font-selection-strategy=character - update to by-character
xmlgraphics-batik-css - update to 1.18-150200.4.10.2
xmlgraphics-batik-slideshow - update to 1.18-150200.4.10.2
xmlgraphics-batik-demo - update to 1.18-150200.4.10.2
xmlgraphics-batik-rasterizer - update to 1.18-150200.4.10.2
xmlgraphics-batik - update to 1.18-150200.4.10.2
xmlgraphics-batik-squiggle - update to 1.18-150200.4.10.2
xmlgraphics-batik-ttf2svg - update to 1.18-150200.4.10.2
xmlgraphics-batik-javadoc - update to 1.18-150200.4.10.2
xmlgraphics-batik-svgpp - update to 1.18-150200.4.10.2
Planning Analytics Local - addressed in versions 2.0.0.101, 2.1.8
fop - update to 2.2-7
xmlgraphics-commons-javadoc - update to 2.10-150200.3.10.2
xmlgraphics-commons - update to 2.10-150200.3.10.2
xmlgraphics-fop - update to 2.10-150200.13.10.1
javapackages-tools - update to 6.3.4-150200.3.15.1
javapackages-filesystem - update to 6.3.4-150200.3.15.1
javapackages-local - update to 6.3.4-150200.3.15.1
javapackages-ivy - update to 6.3.4-150200.3.15.1
javapackages-gradle - update to 6.3.4-150200.3.15.1
python3-javapackages - update to 6.3.4-150200.3.15.1
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
Cloud Tiering Appliance - update to 13.2.0.2.33
IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
External References
Related Security Bulletins
- XXE in Apache FOP
- openEuler update for fop
- SUSE update for javapackages-tools, xmlgraphics-batik, xmlgraphics-commons, xmlgraphics-fop
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM Business Automation Workflow update for Apache XML Graphics FOP
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Planning Analytics Local - IBM Planning Analytics Workspace
- Multiple vulnerabilities in Dell VxRail Appliance
- Multiple vulnerabilities in Dell VxRail Appliance 7.x
- Dell VxRail Appliance 8.x update for third-party components
- Multiple vulnerabilities in Oracle Communications MetaSolv Solution
- Multiple vulnerabilities in Oracle Banking Digital Experience
- Multiple vulnerabilities in Oracle Financial Services Revenue Management and Billing
- Multiple vulnerabilities in Oracle Banking APIs
- XML External Entity injection in Oracle Communications EAGLE Element Management System
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Oracle Business Process Management Suite
- Dell Cloud Tiering Appliance/VE update for third-party components
- Multiple vulnerabilities in Infrastructure Technology
- IBM InfoSphere Information Server update for Apache XML Graphics FOP
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure