CVE-2018-12463

CRITICAL

HP Fortify Software Security Center 17.1, 17.2, 18.1 - Unauthenticated XML External Entity Injection via Crafted DTD

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-12463. PoCs published by alt3kx.

AI-analyzed exploit summary This exploit demonstrates an Out-of-Band XML External Entity (OOB-XXE) vulnerability in Fortify SSC, allowing unauthenticated remote attackers to read arbitrary files or conduct SSRF attacks via crafted DTD in XML requests.

Description

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Exploits (2)

exploitdb WORKING POC VERIFIED
by alt3kx · textwebappsjava
https://www.exploit-db.com/exploits/45027

This exploit demonstrates an Out-of-Band XML External Entity (OOB-XXE) vulnerability in Fortify SSC, allowing unauthenticated remote attackers to read arbitrary files or conduct SSRF attacks via crafted DTD in XML requests.

Classification
Working Poc 95%
Attack Type
Info Leak | Ssrf
Complexity
Moderate
Reliability
Reliable
Target: Fortify Software Security Center (SSC) 17.10, 17.20, 18.10
No auth needed
Prerequisites: Network access to the target server · Ability to send HTTP POST requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 5 stars
by alt3kx · poc
https://github.com/alt3kx/CVE-2018-12463

This repository contains a README documenting CVE-2018-12463, an XXE vulnerability in Fortify Software Security Center (SSC) versions 17.10, 17.20, and 18.10. The vulnerability allows unauthenticated remote attackers to read arbitrary files or perform SSRF attacks via crafted XML requests.

Classification
Writeup 100%
Attack Type
Info Leak | Ssrf
Complexity
Trivial
Reliability
Reliable
Target: Fortify Software Security Center (SSC) 17.10, 17.20, 18.10
No auth needed
Prerequisites: Network access to the vulnerable service
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041286
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45027/

Scores

CVSS v3 9.8
EPSS 0.1385
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (3)
hp/fortify_software_security_center 17.1
hp/fortify_software_security_center 17.2
hp/fortify_software_security_center 18.1
Published Jul 12, 2018
Tracked Since Feb 18, 2026