SB2015071704 - XXE attack in Apache Derby
Published: July 17, 2015
Security Bulletin ID
SB2015071704
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) XXE attack (CVE-ID: CVE-2015-1832)
The vulnerability allows a remote user to conduct XXE attack.The weakness exists due to XML external entity error. Via vectors involving XmlVTI and the XML datatype context-dependent attackers can view arbitrary files that may lead to denial of service.
Successful exploitation of the vulnerability can result in potentially sensitive information disclosure and denial of service on the vulnerable system.
Remediation
Install update from vendor's website.