---
cve: "CVE-2018-6486"
severity: "HIGH"
cvss: 7.3
epss: "1.2%"
vendor: "Micro Focus"
kev: false
exploited: false
published: "2018-02-02 14:29:01"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T09:33:52+02:00"
---

# CVE-2018-6486

> 7.3 HIGH

## Beschreibung

XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Gering | warn |

## Referenzen

- <http://www.securityfocus.com/bid/102902>
- <https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03083653>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-6486) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
