#VU12143 XXE attack in WireMock - CVE-2018-9116


Vulnerability identifier: #VU12143

Vulnerability risk: Low

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2018-9116

CWE-ID: CWE-611

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
WireMock
Universal components / Libraries / Software for developers

Vendor: Tom Akehurst

Description
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to the inclusion of remote Document Type Definition (DTD) documents when using XPath or XML matching. A remote attacker can send a specially crafted request, trigger CPU saturation and cause the service to crash. 

Mitigation
Update to version 2.16.0.

Vulnerable software versions

WireMock: 2.13.0 - 2.15.0


External links
https://groups.google.com/forum/#%21topic/wiremock-user/PQ1UQzKZVl0


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability