Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-6486


XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.


Published

2018-02-02T14:29:01.497

Last Modified

2024-11-21T04:10:45.413

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.3 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microfocus fortify_audit_workbench 16.10 Yes
Application microfocus fortify_audit_workbench 16.20 Yes
Application microfocus fortify_audit_workbench 17.10 Yes
Application microfocus fortify_software_security_center 16.10 Yes
Application microfocus fortify_software_security_center 16.20 Yes
Application microfocus fortify_software_security_center 17.10 Yes

References