PT-2021-22874 · Siemens · Teamcenter

Published

2021-09-14

·

Updated

2021-09-28

·

CVE-2021-40356

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Teamcenter versions prior to V12.4.0.8 Teamcenter versions prior to V13.0.0.7 Teamcenter versions prior to V13.1.0.5 Teamcenter versions prior to V13.2.0.2
Description The application contains a XML External Entity Injection (XXE) vulnerability, which could allow an attacker to view files on the application server filesystem. This issue is related to the processing of XML entities, allowing unauthorized access to sensitive data.
Recommendations For versions prior to V12.4.0.8, update to V12.4.0.8 or later. For versions prior to V13.0.0.7, update to V13.0.0.7 or later. For versions prior to V13.1.0.5, update to V13.1.0.5 or later. For versions prior to V13.2.0.2, update to V13.2.0.2 or later.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40356

Affected Products

Teamcenter