XML External Entity Vulnerability in HCL AppScan Source
CVE-2019-16188
7.1HIGH
Summary
HCL AppScan Source prior to version 9.03.13 is vulnerable to XML External Entity (XXE) attacks. This vulnerability allows attackers to craft malicious .ozasmt files that, when imported by a user, can lead to unauthorized access to sensitive files on the local filesystem. The absence of restrictions on external XML Entity Processing results in potential information exposure and may also facilitate denial of service attacks. Users are advised to exercise caution when handling .ozasmt files, especially from untrusted sources.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved