V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-12463
CVE
CriticalConfirmedExploit available

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticate…

CVSS
9.8
Critical
EPSS
0.22
p95
Published
2018-01-01
Updated
2018-01-01
Description

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Tags · CWE
Pre-auth
CWE-611
CAPEC-221
Affected products
Fortify_software_security_center
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.219 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
45027
exploitdb · https://www.exploit-db.com/exploits/45027
Enterprise
CVE-2018-12463
github-poc · https://github.com/alt3kx/CVE-2018-12463
Enterprise
Affected software
ProductVendorStatus
fortify_software_security_center*Tracked
Source databases
CVE