Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Alex Oree

#33525de 56,330
8.1CVSS total
Vulnerabilidades · 1
PT-2018-11570
8.1
2018-02-09
Apache · Apache Juddi · CVE-2018-1307
**Name of the Vulnerable Software and Affected Versions** Apache jUDDI versions 3.2 through 3.3.4 **Description** The issue concerns a lack of protection against entity expansion and DTD type of attacks when using the WADL2Java or WSDL2Java classes to parse local or remote XML documents. These classes mediate the data structures into UDDI data structures. **Recommendations** For Apache jUDDI versions 3.2 through 3.3.4, update to version 3.3.5 to resolve the issue.