CVE-2016-2019XML External Entity (XXE) Injection in HP Systems Insight Manager

Severity
8.1HIGHNVD
GHSA9.8
EPSS
0.3%
top 49.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 8
Latest updateMay 17

Description

HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

4
GHSA
GHSA-q4m4-r37h-mh88: HPE Systems Insight Manager (SIM) before 72022-05-17
GHSA
Improper Restriction of XML External Entity Reference in jackson-mapper-asl2020-02-04
OSV
wpa vulnerabilities2019-04-10
CVEList
CVE-2016-2019: HPE Systems Insight Manager (SIM) before 72016-06-08

💥Exploits & PoCs

1
Exploit-DB
ManageEngine opManager 12.3.150 - Authenticated Code Execution2019-08-14

📋Vendor Advisories

3
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability2021-03-09
Red Hat
hostapd: Not preventig the use of low quality PRNG in EAP mode leads to insufficient entropy2020-02-27
Red Hat
struts: Bypassing token validation triggered by malicious expression2016-06-17

💬Community

3
Bugzilla
CVE-2019-10172 jackson-mapper-asl: XML external entity similar to CVE-2016-37202019-05-29
Bugzilla
CVE-2016-5824 libical: Multiple use-after-free vulnerabilities2016-09-12
Bugzilla
CVE-2016-3081 Struts2: RCE via method: prefix when Dynamic Method Invocation is enabled (S2-032)2016-04-27
CVE-2016-2019 — XML External Entity (XXE) Injection | cvebase