Multiple HP Fortify Products CVE-2018-6486 XML External Entity Injection Vulnerability
BID:102902
CVE-2018-6486 |Info
Multiple HP Fortify Products CVE-2018-6486 XML External Entity Injection Vulnerability
| Bugtraq ID: | 102902 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-6486 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2018 12:00AM |
| Updated: | Jan 26 2018 12:00AM |
| Credit: | Jakub Palaczynski |
| Vulnerable: |
HP Fortify Software Security Center 17.10 HP Fortify Software Security Center 16.20 HP Fortify Software Security Center 16.10 HP Fortify Audit Workbench 17.10 HP Fortify Audit Workbench 16.20 HP Fortify Audit Workbench 16.10 |
| Not Vulnerable: |
HP Fortify Software Security Center 17.20 HP Fortify Audit Workbench 17.20 |
Discussion
Multiple HP Fortify Products CVE-2018-6486 XML External Entity Injection Vulnerability
Multiple HP Fortify products are prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or cause denial-of-service condition.
The following products are vulnerable:
Fortify Audit Workbench 16.10, 16.20 and 17.10
Fortify Software Security Center 16.10, 16.20 and 17.10
Multiple HP Fortify products are prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to gain access to sensitive information or cause denial-of-service condition.
The following products are vulnerable:
Fortify Audit Workbench 16.10, 16.20 and 17.10
Fortify Software Security Center 16.10, 16.20 and 17.10
Exploit / POC
Multiple HP Fortify Products CVE-2018-6486 XML External Entity Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].