Back to search
CVE-2016-5002
Published: Oct 27, 2017
Modified: Feb 13, 2025
PUBLISHED
Description
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20160712 Vulnerabilities in Apache Archiva
mailing-list
x_refsource_MLIST
1036294
vdb-entry
x_refsource_SECTRACK
apache-archiva-cve20165002-ssrf(115042)
vdb-entry
x_refsource_XF
91736
vdb-entry
x_refsource_BID
RHSA-2018:3768
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now