« Back to list

CVE-2019-4391

Status: ModifiedHigh (8.2)—

HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-4391",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "HCL AppScan Standard Edition",
          "versions": [
            {
              "status": "affected",
              "version": "HCL AppScan Standard versions 9.x and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-07T16:15:17.900",
  "references": [
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0077917",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0077917",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data"
    },
    {
      "lang": "es",
      "value": "HCL AppScan Standard es vulnerable a un ataque de tipo XML External Entity Injection (XXE) cuando se procesa datos XML."
    }
  ],
  "lastModified": "2026-06-17T02:36:28.383",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hcltech:appscan:*:*:*:*:standard:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "588803E7-26CE-415E-9BEB-D74E392345F0",
              "versionEndIncluding": "9.0.3.14"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}