CVE-2018-6489

CRITICAL

Micro Focus Project and Portfolio Management Center 9.32 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0030
EPSS Percentile 53.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (1)
microfocus/project_and_portfolio_management_center 9.32
Published Feb 22, 2018
Tracked Since Feb 18, 2026