HIGH

CVE-2011-3600

CVSS v3

7.5

HIGH

EPSS Score

57.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.

Technical details

Published
11/26/2019

Frequently asked questions

What is CVE-2011-3600?

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.

Is CVE-2011-3600 actively exploited?

Active exploitation of CVE-2011-3600 has not been confirmed. The EPSS score is 57.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2011-3600?

CVE-2011-3600 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2011-3600 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

Other 2011 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).