PT-2021-21649 · Altova · Altova Mobiletogether Server

Published

2021-08-10

·

Updated

2021-08-18

·

CVE-2021-37425

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Altova MobileTogether Server versions prior to 7.3 SP1
Description The issue allows XXE attacks. Specifically, it enables attacks such as InfoSetChanges/Changes against the "/workflowmanagement" API endpoint, or reading the mobiletogetherserver.cfg file and then accessing the certificate and private key.
Recommendations For versions prior to 7.3 SP1, update to version 7.3 SP1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/workflowmanagement" API endpoint until a patch is available. Avoid using sensitive configuration files, such as mobiletogetherserver.cfg, in unsecured locations to minimize the risk of exploitation.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37425

Affected Products

Altova Mobiletogether Server