PT-2021-22874 · Siemens · Teamcenter
Published
2021-09-14
·
Updated
2021-09-28
·
CVE-2021-40356
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Teamcenter versions prior to V12.4.0.8
Teamcenter versions prior to V13.0.0.7
Teamcenter versions prior to V13.1.0.5
Teamcenter versions prior to V13.2.0.2
Description
The application contains a XML External Entity Injection (XXE) vulnerability, which could allow an attacker to view files on the application server filesystem. This issue is related to the processing of XML entities, allowing unauthorized access to sensitive data.
Recommendations
For versions prior to V12.4.0.8, update to V12.4.0.8 or later.
For versions prior to V13.0.0.7, update to V13.0.0.7 or later.
For versions prior to V13.1.0.5, update to V13.1.0.5 or later.
For versions prior to V13.2.0.2, update to V13.2.0.2 or later.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamcenter