MidnightBSD

Advisories for dom4j_project

CVE-2018-1000632 MEDIUM

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-91,

Products Affected

Vendor Product Version
oracle utilities_framework 4.4.0.2
oracle utilities_framework 4.2.0.3.0
oracle utilities_framework 2.2.0
netapp snapmanager -
redhat satellite 6.6
oracle retail_integration_bus 16.0
debian debian_linux 8.0
oracle primavera_p6_enterprise_project_portfolio_management *
redhat jboss_enterprise_application_platform 6.4.0
oracle retail_integration_bus 15.0
oracle rapid_planning 12.1
oracle flexcube_investor_servicing 12.0.4
oracle flexcube_investor_servicing 12.3.0
dom4j_project dom4j *
oracle rapid_planning 12.2
oracle flexcube_investor_servicing 12.1.0
oracle utilities_framework 4.2.0.2.0
oracle utilities_framework 4.4.0.0.0
redhat satellite_capsule 6.6
netapp snap_creator_framework -
oracle utilities_framework *
netapp snapcenter -
netapp oncommand_workflow_automation -
redhat jboss_enterprise_application_platform 7.1.0
oracle flexcube_investor_servicing 12.4.0
oracle flexcube_investor_servicing 14.0.0
redhat jboss_enterprise_application_platform 6.0.0