First published: Tue Aug 08 2017(Updated: )
Apache Wink could allow a remote attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data. By using a specially-crafted XML file. A remote attacker could exploit this vulnerability to read arbitrary files or cause a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Wink | <=1.1.1 | |
<=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2245 is an XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier.
The severity of CVE-2010-2245 is high, with a CVSS score of 7.4.
CVE-2010-2245 allows a remote attacker to obtain sensitive information or cause a denial of service by exploiting an XML external entity (XXE) error when processing XML data in Apache Wink 1.1.1 and earlier versions.
A remote attacker can exploit CVE-2010-2245 by using a specially-crafted XML file to read arbitrary files or cause a denial of service.
Yes, you can find references for CVE-2010-2245 at the following links: [1] https://svn.apache.org/repos/asf/wink/trunk/security/CVE-2010-2245.pdf [2] http://marc.info/?l=wink-user&m=127843482925387&w=2 [3] https://exchange.xforce.ibmcloud.com/vulnerabilities/134129