CVE-2018-1000836

CRITICAL

bw-calendar-engine <= 3.12.0 - XML External Entity Injection in IscheduleClient XML Parser

Title source: llm
STIX 2.1

Description

bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the Middle or malicious server.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/Bedework/bw-calendar-engine/issues/3
Third Party Advisory x_refsource_misc
https://0dd.zone/2018/10/28/bw-calendar-engine-XXE-MitM/

Scores

CVSS v3 9.0
EPSS 0.0113
EPSS Percentile 62.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (2)
apereo/bw-calendar-engine < 3.12.0
org.bedework.caleng/bw-calendar-engine 0Maven
Published Dec 20, 2018
Tracked Since Feb 18, 2026