Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-1832

XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.4%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
References
Products affected by CVE-2015-1832
  • Apache » Derby » Version: 10.1.1.0
    cpe:2.3:a:apache:derby:10.1.1.0
  • Apache » Derby » Version: 10.1.2.1
    cpe:2.3:a:apache:derby:10.1.2.1
  • Apache » Derby » Version: 10.1.3.1
    cpe:2.3:a:apache:derby:10.1.3.1
  • Apache » Derby » Version: 10.10.1.1
    cpe:2.3:a:apache:derby:10.10.1.1
  • Apache » Derby » Version: 10.10.2.0
    cpe:2.3:a:apache:derby:10.10.2.0
  • Apache » Derby » Version: 10.11.1.1
    cpe:2.3:a:apache:derby:10.11.1.1
  • Apache » Derby » Version: 10.2.1.6
    cpe:2.3:a:apache:derby:10.2.1.6
  • Apache » Derby » Version: 10.2.2.0
    cpe:2.3:a:apache:derby:10.2.2.0
  • Apache » Derby » Version: 10.3.3.0
    cpe:2.3:a:apache:derby:10.3.3.0
  • Apache » Derby » Version: 10.4.1.3
    cpe:2.3:a:apache:derby:10.4.1.3
  • Apache » Derby » Version: 10.4.2.0
    cpe:2.3:a:apache:derby:10.4.2.0
  • Apache » Derby » Version: 10.5.1.1
    cpe:2.3:a:apache:derby:10.5.1.1
  • Apache » Derby » Version: 10.5.3.0
    cpe:2.3:a:apache:derby:10.5.3.0
  • Apache » Derby » Version: 10.6.1.0
    cpe:2.3:a:apache:derby:10.6.1.0
  • Apache » Derby » Version: 10.6.2.1
    cpe:2.3:a:apache:derby:10.6.2.1
  • Apache » Derby » Version: 10.7.1.1
    cpe:2.3:a:apache:derby:10.7.1.1
  • Apache » Derby » Version: 10.8.1.2
    cpe:2.3:a:apache:derby:10.8.1.2
  • Apache » Derby » Version: 10.8.2.2
    cpe:2.3:a:apache:derby:10.8.2.2
  • Apache » Derby » Version: 10.8.3.0
    cpe:2.3:a:apache:derby:10.8.3.0
  • Apache » Derby » Version: 10.9.1.0
    cpe:2.3:a:apache:derby:10.9.1.0


Contact Us

Shodan ® - All rights reserved