PT-2015-18 · 1с · 1С:Предприятие

Publicado

2015-11-10

·

Atualizado

2015-11-10

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions 1С:Предприятие (affected versions not specified)
Description The issue is related to the dynamic analysis of XML files in the wsisapi.dll library, which is part of the 1С:Предприятие enterprise automation system. It involves the injection of XML, allowing a remote attacker to potentially cause a denial of service and gain access to internal network resources, including the file system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02197

Produtos afetados

1С:Предприятие