« Volver al listado

CVE-2015-0923

Estado: ModificadaMedia (5)—

The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-0923",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-02-14T03:01:17.927",
  "references": [
    {
      "url": "http://www.kb.cert.org/vuls/id/377644",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/377644",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue."
    },
    {
      "lang": "es",
      "value": "El método ContentBlockEx en Workarea/ServerControlWS.asmx en Ektron Content Management System (CMS) 8.5 y 8.7 anterior a 8.7sp2 y 9.0 anterior a sp1 permite a atacantes remotos leer ficheros arbitrarios a través de una declaración de entidad externa en conjunto con una referencia de entidad dentro de un documento XML nombrado en el parámetro xslt, relacionado con un problema de entidad externa XML (XXE)."
    }
  ],
  "lastModified": "2026-06-17T00:21:09.493",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ektron:ektron_content_management_system:8.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CE05608-CA88-4EC1-A99B-57CBC3F82E43"
            },
            {
              "criteria": "cpe:2.3:a:ektron:ektron_content_management_system:8.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "680BB0D0-703E-4858-B96F-E046B5F8007E"
            },
            {
              "criteria": "cpe:2.3:a:ektron:ektron_content_management_system:8.7.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "798E5E7C-390A-45E1-BD66-F38877A895D5"
            },
            {
              "criteria": "cpe:2.3:a:ektron:ektron_content_management_system:8.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7229DF65-AD95-45E6-AE9F-283CD955F0F1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/611.html\">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>",
  "sourceIdentifier": "cret@cert.org"
}