XML External Entity Vulnerability in CA Release Automation
CVE-2015-8698
7.1HIGH
What is CVE-2015-8698?
An XML External Entity (XXE) vulnerability exists in specific versions of CA Release Automation, allowing remote attackers to read sensitive arbitrary files or induce a denial of service through crafted XML requests. This issue arises when an XML entity reference is insufficiently validated, leading to the potential exposure of sensitive system information and the disruption of service availability.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved