CVE-2018-6486: Micro Focus Fortify Audit Workbench

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.

Affected products

  • Micro Focus Fortify Audit Workbench: version 16.10 only; version 16.20 only; version 17.10 only
  • Micro Focus Fortify Software Security Center: version 16.10 only; version 16.20 only; version 17.10 only

Published 2018-02-02. Last modified 2026-06-17.