Vulnerabilities > CVE-2010-2245 - XXE vulnerability in Apache Wink

047910
CVSS 7.4 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH
network
high complexity
apache
CWE-611

Summary

XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.

Vulnerable Configurations

Part Description Count
Application
Apache
4