XML External Entity Vulnerability in Veeam ONE by Veeam Software
CVE-2020-15418
What is CVE-2020-15418?
This vulnerability affects Veeam ONE, enabling remote attackers to disclose sensitive information on impacted systems. It arises from the improper handling of XML External Entity (XXE) references in the SSRSReport class. An attacker can exploit this flaw by sending specially crafted XML documents that reference a URI, compelling the XML parser to access external content. This can lead to unauthorized disclosure of file contents within the context of the SYSTEM, potentially compromising sensitive data directly from the server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ONE 10.0.0.750_20200415
References
EPSS Score
21% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved