XML External Entity Vulnerability in HCL AppScan Source
CVE-2019-16188

7.1HIGH

Key Information:

Vendor
CVE Published:
25 September 2019

Summary

HCL AppScan Source prior to version 9.03.13 is vulnerable to XML External Entity (XXE) attacks. This vulnerability allows attackers to craft malicious .ozasmt files that, when imported by a user, can lead to unauthorized access to sensitive files on the local filesystem. The absence of restrictions on external XML Entity Processing results in potential information exposure and may also facilitate denial of service attacks. Users are advised to exercise caution when handling .ozasmt files, especially from untrusted sources.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.