CVE-2021-38555

Description

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an applications processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
1.272

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-40146,CVE-2021-38555 are fixed in Apache-apache-any23 2.5Windows
Vulnerabilities CVE-2021-40146,CVE-2021-38555 are fixed in Apache-apache-any23 for Linux 2.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234