Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-3600

43
FAUCET Score

CVE-2011-3600 is an External Entity Injection vulnerability affecting Apache OFBiz versions 16.11.01 to 16.11.04, specifically within the /webtools/control/xmlrpc endpoint. This high-severity vulnerability (CVSS 7.5) allows unauthenticated attackers to disclose file contents, probe network ports, and determine file existence through crafted DOCTYPE declarations. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist for detection, and the vulnerability has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 16.11.01, <= 16.11.04CPE matchmatch criteria
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
15.91%
Probability of exploitation in next 30 days
EPSS Percentile
96.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Nuclei: CVE-2011-3600 · Jan 6, 2026
This CVE's current EPSS score of 0.1591 is in the 95th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

debianpatch availablevia osv
Product: libxmlrpc3-javaFixed in: 3.1.3-1
redhatpatch availablevia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: xmlrpc3

Vendor Advisories (2)

debianCVE-2011-3600HIGH

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.

Nov 26, 2019
redhatCVE-2011-3600Low

XML-RPC SAX parser information exposure

Feb 6, 2010

References

mail-archives.apache.org / mod_mbox/ofbiz-user/201810.mbox/%3Cfad45546-af86-0293-9ea7-014553474b30%40apache.org%3E
access.redhat.com / security/cve/cve-2011-3600
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
lists.apache.org / thread.html/7793319ae80ec350f7b82a8763460944f120ebe447f14a12155d0550%40%3Ccommits.ofbiz.apache.org%3E
security-tracker.debian.org / tracker/CVE-2011-3600
Third Party Advisory