peter bassill · operator
$ cve CVE-2015-1833 JSON

CVE-2015-1833 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 55% (pctl 99)

Patch early

A public exploit exists.

Description

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS55.03% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2015-05-29
Last modified2026-06-17

Affected (1)

VendorProduct
apachejackrabbit

Public exploits

SourceTitleDate
exploit-dbApache JackRabbit - WebDAV XML External Entity2015-05-26

References

→ the Explorer  ·  watch your stack  ·  NVD