The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Aug 28, 2015 | Sep 16, 2013 |
| Apple Osx Php | — | Upgrade macOS to the latest versionApply OS X security update 2013-004 | Sep 17, 2013 | Sep 17, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 30, 2015 |
| Gentoo Linux | — | Upgrade dev-lang/php. | Oct 30, 2017 | Sep 16, 2013 |
| Php | — | Upgrade to PHP version 5.4.12Upgrade to PHP version 5.3.22 | Sep 18, 2013 | Sep 16, 2013 |
| Suse | — | Upgrade php7-xmlreaderUpgrade php5-develUpgrade php7-sqliteUpgrade php7-mysqlUpgrade php7Upgrade php7-domUpgrade php72-develUpgrade php7-pgsqlUpgrade php7-tokenizerUpgrade php7-ctypeUpgrade php7-iconvUpgrade php7-pdoUpgrade php7-xmlwriterUpgrade php7-develUpgrade apache2-mod_php7Upgrade php7-json | Aug 9, 2024 | Sep 16, 2013 |
| Ubuntu | — | Upgrade php5 | Nov 19, 2024 | Sep 16, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub