CVE-2018-6486
Summary
| CVE | CVE-2018-6486 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-02 14:29:00 UTC |
| Updated | 2023-11-07 02:59:00 UTC |
| Description | XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microfocus | Fortify Audit Workbench | 16.10 | All | All | All |
| Application | Microfocus | Fortify Audit Workbench | 16.20 | All | All | All |
| Application | Microfocus | Fortify Audit Workbench | 17.10 | All | All | All |
| Application | Microfocus | Fortify Audit Workbench | 16.10 | All | All | All |
| Application | Microfocus | Fortify Audit Workbench | 16.20 | All | All | All |
| Application | Microfocus | Fortify Audit Workbench | 17.10 | All | All | All |
| Application | Microfocus | Fortify Software Security Center | 16.10 | All | All | All |
| Application | Microfocus | Fortify Software Security Center | 16.20 | All | All | All |
| Application | Microfocus | Fortify Software Security Center | 17.10 | All | All | All |
| Application | Microfocus | Fortify Software Security Center | 16.10 | All | All | All |
| Application | Microfocus | Fortify Software Security Center | 16.20 | All | All | All |
| Application | Microfocus | Fortify Software Security Center | 17.10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple HP Fortify Products CVE-2018-6486 XML External Entity Injection Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| MySupport - Micro Focus Software Support | softwaresupport.softwaregrp.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.