CVE-2018-19371: XEE
Published Jan 2, 2019
·Updated
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
Affected Software
1 affected component
SDL Web Content Manager=8.5.0
Event History
Jan 2, 2019
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19371?
CVE-2018-19371 has been classified as a high severity vulnerability due to its potential to compromise sensitive files on the system.
2
How do I fix CVE-2018-19371?
To fix CVE-2018-19371, ensure that you upgrade to a patched version of SDL Web Content Manager beyond 8.5.0.
3
What type of vulnerability is CVE-2018-19371?
CVE-2018-19371 is an XML External Entity (XXE) vulnerability affecting SDL Web 8.5.0.
4
What can be affected by CVE-2018-19371?
CVE-2018-19371 can allow attackers to read sensitive files from the server's filesystem.
5
Is CVE-2018-19371 specific to certain versions of SDL Web?
Yes, CVE-2018-19371 specifically affects SDL Web Content Manager version 8.5.0.