Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-8038

Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.415
EPSS Ranking 97.2%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
References
Products affected by CVE-2018-8038


Contact Us

Shodan ® - All rights reserved