Vulnerabilities > CVE-2018-5758 - XXE vulnerability in Aurea Jive-N 9.0.2.1

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
aurea
CWE-611

Summary

The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file, allowing attackers to read arbitrary files.

Vulnerable Configurations

Part Description Count
Application
Aurea
1