peter bassill · operator
$ cve CVE-2018-12463 JSON

CVE-2018-12463 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 13.8% (pctl 96)

Patch early

A public exploit exists.

Description

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.85% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploityes
Published2018-07-12
Last modified2026-06-17

Affected (1)

VendorProduct
hpfortify software security center

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD