Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-1832


XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.


Published

2016-10-03T21:59:02.533

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 9.1 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-399
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache derby 10.1.1.0 Yes
Application apache derby 10.1.2.1 Yes
Application apache derby 10.1.3.1 Yes
Application apache derby 10.2.1.6 Yes
Application apache derby 10.2.2.0 Yes
Application apache derby 10.3.3.0 Yes
Application apache derby 10.4.1.3 Yes
Application apache derby 10.4.2.0 Yes
Application apache derby 10.5.1.1 Yes
Application apache derby 10.5.3.0 Yes
Application apache derby 10.6.1.0 Yes
Application apache derby 10.6.2.1 Yes
Application apache derby 10.7.1.1 Yes
Application apache derby 10.8.1.2 Yes
Application apache derby 10.8.2.2 Yes
Application apache derby 10.8.3.0 Yes
Application apache derby 10.9.1.0 Yes
Application apache derby 10.10.1.1 Yes
Application apache derby 10.10.2.0 Yes
Application apache derby 10.11.1.1 Yes

References