CVE-2018-1000632: Debian Linux
High severity, CVSS 7.5. EPSS: 6.6% chance of exploitation in the next 30 days.
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Affected products
- Debian Debian Linux: version 8.0 only
- DOM4J Project DOM4J: from 2.0.0, before 2.0.3 (fixed in 2.0.3); from 2.1.0, before 2.1.1 (fixed in 2.1.1)
- Netapp Oncommand Workflow Automation: affected versions not specified
- Netapp Snap Creator Framework: affected versions not specified
- Netapp Snapcenter: affected versions not specified
- Netapp Snapmanager: affected versions not specified
- Oracle Flexcube Investor Servicing: version 12.0.4 only; version 12.1.0 only; version 12.3.0 only; version 12.4.0 only; version 14.0.0 only
- Oracle Primavera p6 Enterprise Project Portfolio Management: from 16.1.0.0, up to and including 16.2.20.1; from 17.1.0.0, up to and including 17.12.17.1; from 18.1.0.0, up to and including 18.8.19.0; from 19.12.0.0, up to and including 19.12.6.0
- Oracle Rapid Planning: version 12.1 only; version 12.2 only
- Oracle Retail Integration Bus: version 15.0 only; version 16.0 only
- Oracle Utilities Framework: from 4.3.0.2.0, up to and including 4.3.0.6.0; version 2.2.0 only; version 4.2.0.2.0 only; version 4.2.0.3.0 only; version 4.4.0.0.0 only; version 4.4.0.2 only
- Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only; version 7.1.0 only
- Red Hat Satellite: version 6.6 only
- Red Hat Satellite Capsule: version 6.6 only
Published 2018-08-20. Last modified 2026-06-17.