CVE-2019-4391: XEE
Published Apr 7, 2020
·Updated
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
Affected Software
1 affected component
hcltech Appscan<=9.0.3.14
Event History
Apr 7, 2020
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-4391?
CVE-2019-4391 is rated as a medium severity vulnerability due to the potential for data exposure via an XML External Entity Injection.
2
How do I fix CVE-2019-4391?
To fix CVE-2019-4391, users should upgrade to a version of HCL AppScan Standard that is later than 9.0.3.14.
3
What types of attacks can CVE-2019-4391 facilitate?
CVE-2019-4391 can facilitate XML External Entity Injection attacks, which may lead to sensitive data extraction or server-side request forgery.
4
Is my application affected by CVE-2019-4391?
If you are using HCL AppScan Standard version 9.0.3.14 or earlier, your application is affected by CVE-2019-4391.
5
What is the impact of CVE-2019-4391 on HCL AppScan Standard?
The impact of CVE-2019-4391 includes potential exposure of sensitive information and possible unauthorized access to system resources.