CVE-2018-17186: XEE
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17186?
CVE-2018-17186 is a vulnerability that allows an administrator with workflow definition entitlements to perform malicious operations using DTD, such as file read, file write, and code execution.
Which software is affected by CVE-2018-17186?
Apache Syncope versions 2.0.0 to 2.0.11 and versions 2.1.0 to 2.1.2 are affected by CVE-2018-17186.
How severe is CVE-2018-17186?
CVE-2018-17186 has a severity rating of 7.2 (high).
How can I fix CVE-2018-17186?
To fix CVE-2018-17186, it is recommended to upgrade to a version of Apache Syncope that is not affected by the vulnerability.
Where can I find more information about CVE-2018-17186?
More information about CVE-2018-17186 can be found at the following reference: https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions