Total vulnerabilities in the database
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.
Software | From | Fixed in |
---|---|---|
apache / log4net | - | 2.0.10 |
fedoraproject / fedora | 30 | 30.x |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / fedora | 32 | 32.x |
oracle / application_testing_suite | 13.3.0.1 | 13.3.0.1.x |
oracle / hospitality_simphony | 19.1.3 | 19.1.3.x |
oracle / hospitality_simphony | 18.2.7.2 | 18.2.7.2.x |
oracle / hospitality_opera_5 | 5.5 | 5.5.x |
oracle / hospitality_opera_5 | 5.6 | 5.6.x |
![]() |
- | 2.0.10 |