Security Advisory

CVE-2018-8819

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-06-14 20:00:00
Last updated 2024-08-05 07:02:26
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.