UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via malicious plugins.xml file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-12-20T15:00:00Z
Updated: 2024-09-17T01:46:52.110Z
Reserved: 2018-12-20T00:00:00Z
Link: CVE-2018-1000837
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2018-12-20T15:29:01.703
Modified: 2019-09-11T16:53:42.780
Link: CVE-2018-1000837
Redhat
No data.