apache xml-rpc CVE-2016-5002 is a vulnerability in Apache Xml Rpc
Published on October 27, 2017

XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.

Vendor Advisory NVD


Products Associated with CVE-2016-5002

Want to know whenever a new CVE is published for Apache Xml Rpc? stack.watch will email you.

 

Exploit Probability

EPSS
3.53%
Percentile
87.48%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.