#VU735 XXE attack in Apache Derby


Published: 2016-10-04 | Updated: 2018-03-21

Vulnerability identifier: #VU735

Vulnerability risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2015-1832

CWE-ID: CWE-611

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Apache Derby
Server applications / Database software

Vendor: Apache Foundation

Description
The vulnerability allows a remote user to conduct XXE attack.
The weakness exists due to XML external entity error. Via vectors involving XmlVTI and the XML datatype context-dependent attackers can view arbitrary files that may lead to denial of service.
Successful exploitation of the vulnerability can result in potentially sensitive information disclosure and denial of service on the vulnerable system.

Mitigation
Update to 10.12.1.1.

Vulnerable software versions

Apache Derby: 10.1.1 - 10.11.1.1


External links
http://svn.apache.org/viewvc?view=revision&revision=1691461


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability