VYPR
Unrated severityNVD Advisory· Published Feb 22, 2018· Updated Aug 5, 2024

CVE-2018-6489

CVE-2018-6489

Description

XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to allow XML External Entity (XXE)

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center 9.32 allows remote attackers to read files or perform SSRF attacks.

Vulnerability

Micro Focus Project and Portfolio Management Center version 9.32 contains an XML External Entity (XXE) vulnerability. The application fails to properly restrict XML external entity references when parsing XML input, allowing an attacker to inject malicious XML content. This issue is documented in Micro Focus security bulletin KM03014426 [1].

Exploitation

An unauthenticated attacker with network access can send a crafted XML payload to the vulnerable endpoint. The XML parser will process external entities, enabling the attacker to read local files, conduct server-side request forgery (SSRF), or potentially cause a denial of service. No prior authentication is required.

Impact

Successful exploitation leads to information disclosure of sensitive files (e.g., configuration files), internal network scanning via SSRF, or application disruption. The attacker does not gain direct code execution but can extract data from the server's filesystem.

Mitigation

Micro Focus has released a security fix as part of a patch; refer to the bulletin KM03014426 for specific patch details [1]. Users should apply the latest fixes for Project and Portfolio Management Center 9.32. No workarounds are provided.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.