CVE-2015-1832: XEE
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-1832?
CVE-2015-1832 is a vulnerability in Apache Derby that allows a remote attacker to obtain sensitive information or cause a denial of service.
What is the severity of CVE-2015-1832?
The severity of CVE-2015-1832 is critical with a CVSS score of 9.1.
How does CVE-2015-1832 affect Apache Derby?
CVE-2015-1832 affects Apache Derby versions before 10.12.1.1.
How can a remote attacker exploit CVE-2015-1832?
A remote attacker can exploit CVE-2015-1832 by leveraging XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby.
Is there a fix available for CVE-2015-1832?
Yes, the fix for CVE-2015-1832 is available in Apache Derby version 10.12.1.1 and later.