Bug 1381474 (CVE-2015-1832) - CVE-2015-1832 Apache Derby: XXE attack possible by using XmlVTI and the XML datatype
Summary: CVE-2015-1832 Apache Derby: XXE attack possible by using XmlVTI and the XML d...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2015-1832
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1381475
Blocks: 1381477
TreeView+ depends on / blocked
 
Reported: 2016-10-04 08:44 UTC by Andrej Nemec
Modified: 2019-09-29 13:57 UTC (History)
13 users (show)

Fixed In Version: derby 10.12.1.1
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-08 02:59:19 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2016-10-04 08:44:42 UTC
Apache Derby could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML datatype and XmlVTI. An attacker could exploit this vulnerability to read arbitrary files on the system or cause a denial of service.

Upstream bug:

https://issues.apache.org/jira/browse/DERBY-6807

Upstream patch:

https://svn.apache.org/viewvc?view=revision&revision=1691461

Comment 1 Andrej Nemec 2016-10-04 08:45:55 UTC
Created derby tracking bugs for this issue:

Affects: fedora-all [bug 1381475]


Note You need to log in before you can comment on or make changes to this bug.