CVE-2017-15691
Description
In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache uimaDUCC prior to 2.2.2, this vulnerability relates to an XML external entity expansion (XXE) capability of various XML parsers. UIMA as part of its configuration and operation may read XML from various sources, which could be tainted in ways to cause inadvertent disclosure of local files or other internal content.
Risk Information
Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.976
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimaj-core 3.0.0 | Windows |
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimaj-core 2.10.2 | Windows |
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimafit-core 2.4.0 | Windows |
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimaj-as-core 2.10.2 | Windows |
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimaj-core for Linux 3.0.0 | Linux |
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimaj-core for Linux 2.10.2 | Linux |
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimafit-core for Linux 2.4.0 | Linux |
| Vulnerabilities CVE-2017-15691 are fixed in Apache-uimaj-as-core for Linux 2.10.2 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234