CVE-2018-12463: MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12463?
CVE-2018-12463 has a medium severity rating, indicating a moderate risk to affected systems.
How do I fix CVE-2018-12463?
To fix CVE-2018-12463, update Fortify Software Security Center to the latest version that addresses this vulnerability.
What types of attacks can CVE-2018-12463 enable?
CVE-2018-12463 can enable arbitrary file reading and server-side request forgery (SSRF) attacks.
Which versions of Fortify Software Security Center are affected by CVE-2018-12463?
CVE-2018-12463 affects Fortify Software Security Center versions 17.1, 17.2, and 18.1.
Who is at risk due to CVE-2018-12463?
Remote unauthenticated users can exploit CVE-2018-12463 if they have access to submit XML requests.