CVE-2018-17186

HIGH

Apache Syncope - XML External Entity Injection

Title source: llm
STIX 2.1

Description

An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0056
EPSS Percentile 68.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (2)
apache/syncope 2.0.0 - 2.0.11
org.apache.syncope/syncope-core 0 - 2.0.11Maven
Published Nov 06, 2018
Tracked Since Feb 18, 2026