CVE-2018-1000632 Details
Description
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-91 | XML Injection (aka Blind XPath Injection) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dom4j project dom4j | >= 2.0.0, < 2.0.3 >= 2.1.0, < 2.1.1 |
CPE
Remediation
| |
| debian debian linux | 8.0 |
CPE
Remediation
| |
| oracle flexcube investor servicing | 12.0.4 12.1.0 12.3.0 12.4.0 14.0.0 |
CPE
Remediation
| |
| oracle primavera p6 enterprise project portfolio management | >= 16.1.0.0, <= 16.2.20.1 >= 17.1.0.0, <= 17.12.17.1 >= 18.1.0.0, <= 18.8.19.0 >= 19.12.0.0, <= 19.12.6.0 |
CPE
Remediation
| |
| oracle rapid planning | 12.1 12.2 |
CPE
Remediation
| |
| oracle retail integration bus | 15.0 16.0 |
CPE
Remediation
| |
| oracle utilities framework | >= 4.3.0.2.0, <= 4.3.0.6.0 2.2.0 4.2.0.2.0 4.2.0.3.0 4.4.0.0.0 4.4.0.2 |
CPE
Remediation
| |
| redhat satellite | 6.6 |
CPE
Remediation
| |
| redhat satellite capsule | 6.6 |
CPE
Remediation
| |
| redhat jboss enterprise application platform | 6.0.0 6.4.0 7.1.0 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 5.0 |
CPE
Remediation
| |
| netapp oncommand workflow automation | All versions |
CPE
Remediation
| |
| netapp snap creator framework | All versions |
CPE
Remediation
| |
| netapp snapcenter | All versions |
CPE
Remediation
| |
| netapp snapmanager | All versions |
CPE
Remediation
| |
Change History
28 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Sep 7, 2021 | CVE Modified | [email protected] |
| Jun 14, 2021 | CVE Modified | [email protected] |
| May 12, 2021 | CVE Modified | [email protected] |
| May 12, 2021 | CVE Modified | [email protected] |
| Jul 23, 2020 | Modified Analysis | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| Apr 15, 2020 | CVE Modified | [email protected] |
| Nov 12, 2019 | CVE Modified | [email protected] |
| Oct 24, 2019 | CVE Modified | [email protected] |
| Jun 10, 2019 | CVE Modified | [email protected] |
| Jun 4, 2019 | CVE Modified | [email protected] |
| Jun 3, 2019 | CVE Modified | [email protected] |
| Jun 1, 2019 | CVE Modified | [email protected] |
| May 31, 2019 | CVE Modified | [email protected] |
| May 31, 2019 | CVE Modified | [email protected] |
| May 31, 2019 | CVE Modified | [email protected] |
| May 30, 2019 | CVE Modified | [email protected] |
| May 14, 2019 | CVE Modified | [email protected] |
| Mar 8, 2019 | Modified Analysis | [email protected] |
| Feb 20, 2019 | CVE Modified | [email protected] |
| Feb 19, 2019 | CVE Modified | [email protected] |
| Jan 16, 2019 | CVE Modified | [email protected] |
| Oct 31, 2018 | Initial Analysis | [email protected] |
| Sep 25, 2018 | CVE Modified | [email protected] |