CVE-2018-1000632

HIGH

dom4j 2.0.0-2.0.3 - XML Injection via Element.addElement or Element.addAttribute

Title source: llm
STIX 2.1

Description

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

References (29)

Core 29
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/09/msg00028.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0364
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0362
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0365
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0380
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1160
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1162
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1159
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1161
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3172
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory x_refsource_confirm
https://github.com/dom4j/dom4j/issues/48
Exploit, Third Party Advisory x_refsource_misc
https://ihacktoprotect.com/post/dom4j-xml-injection/
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190530-0001/

Scores

CVSS v3 7.5
EPSS 0.0639
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-91
Status published
Products (29)
debian/debian_linux 8.0
dom4j/dom4j 0Maven
dom4j_project/dom4j 2.0.0 - 2.0.3
netapp/oncommand_workflow_automation
netapp/snap_creator_framework
netapp/snapcenter
netapp/snapmanager (2 CPE variants)
oracle/flexcube_investor_servicing 12.0.4
oracle/flexcube_investor_servicing 12.1.0
oracle/flexcube_investor_servicing 12.3.0
... and 19 more
Published Aug 20, 2018
Tracked Since Feb 18, 2026