cbcvebase.
CVE-2017-12620
published 2017-10-03

CVE-2017-12620: When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications…

PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.02%
85.9th percentile
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects applications that load models or dictionaries from untrusted sources. The versions 1.5.0 to 1.5.3, 1.6.0, 1.7.0 to 1.7.2, 1.8.0 to 1.8.1 of Apache OpenNLP are affected.

Affected

14 ranges
VendorProductVersion rangeFixed in
apacheopennlp
apacheopennlp
apacheopennlp
apacheopennlp
apacheopennlp
apacheopennlp
apacheopennlp
apacheopennlp
apacheopennlp
apacheopennlp
apache_software_foundationapache_opennlp
apache_software_foundationapache_opennlp
apache_software_foundationapache_opennlp
apache_software_foundationapache_opennlp

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.