CVE-2017-12620

Description

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.018

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-12620 are fixed in Apache-opennlp-tools 1.8.2Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1.7Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.0Windows
Vulnerabilities CVE-2017-12620 are fixed in Apache-opennlp-tools for Linux 1.8.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234