CVE-2018-17912

An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.
References
Link Resource
http://www.securityfocus.com/bid/105804 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-305-04 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/105804 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-305-04 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:sauter-controls:case_suite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:55

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/105804 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/105804 - Third Party Advisory, VDB Entry
References () https://ics-cert.us-cert.gov/advisories/ICSA-18-305-04 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-18-305-04 - Third Party Advisory, US Government Resource

Information

Published : 2018-11-02 14:29

Updated : 2024-11-21 03:55


NVD link : CVE-2018-17912

Mitre link : CVE-2018-17912

CVE.ORG link : CVE-2018-17912


JSON object : View

Products Affected

sauter-controls

  • case_suite
CWE
CWE-611

Improper Restriction of XML External Entity Reference