AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-15712

MEDIUM · CVSS 6.5 EPSS 2.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-02-19 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It affects Apache.

CVE
CVE-2017-15712
Severity
MEDIUM
CVSS
6.5
EPSS
2.50%
Apache

Original NVD Description

Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive files on the Oozie server host.

Related CVEs

Other vulnerabilities affecting the same vendor(s)