Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Derby 资源管理错误漏洞
Vulnerability Description
Apache Derby是美国阿帕奇(Apache)基金会的一套开源的数据库管理系统。 Apache Derby 10.12.1.1之前版本中的SqlXmlUtil代码存在资源管理错误漏洞。攻击者可利用该漏洞读取任意文件,或造成拒绝服务(资源耗尽)。
CVSS Information
N/A
Vulnerability Type
N/A