PT-2022-12895 · Signiant · Signiant Manager+Agents

Published

2022-01-29

·

Updated

2022-02-04

·

CVE-2021-46660

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Signiant Manager+Agents versions prior to 15.1
Description The issue allows XML External Entity (XXE) attacks. XML External Entity attacks occur when an application parses XML input that contains malicious external entities, which can lead to sensitive data exposure or other security issues.
Recommendations For versions prior to 15.1, update to version 15.1 or later to resolve the issue. As a temporary workaround, consider restricting XML input parsing to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46660

Affected Products

Signiant Manager+Agents