CVE
- Id
- 79109
- CVE No.
- CVE-2015-1832
- Status
- Candidate
- Description
- XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
- Phase
- Assigned (20150217)
- Votes
- None (candidate not yet proposed)
- Comments