PT-2022-16733 · Red Hat+1 · Kie-Server Apis+1
Paramvir Jindal
·
Published
2022-08-09
·
Updated
2023-06-23
·
CVE-2022-2458
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Business Central (affected versions not specified)
Kie-Server APIs (affected versions not specified)
Description
The issue allows an attacker to interfere with an application's processing of XML data through XML external entity injection (XXE). This occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser, causing the product to embed incorrect documents into its output. The XXE leads to External Service interaction and Internal file read.
Recommendations
For Business Central, consider disabling the processing of external XML entities until a patch is available.
For Kie-Server APIs, restrict access to XML documents that can contain external entities to minimize the risk of exploitation.
As a temporary workaround, consider configuring the XML parser to only process XML entities within the intended sphere of control.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Business Central
Kie-Server Apis