PT-2023-6142 · Unknown · Vbase Automation Base

Kimiya

·

Published

2023-03-21

·

Updated

2025-01-17

·

CVE-2022-43512

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VBASE Automation Base versions prior to 11.7.5
Description The issue is related to incorrect restriction of XML external entity references, which can lead to information disclosure when a valid user opens a specially crafted file. This may allow an attacker to cause a denial of service or gain unauthorized access to confidential data.
Recommendations For versions prior to 11.7.5, update to version 11.7.5 or later to resolve the issue. As a temporary workaround, consider restricting access to specially crafted files that could exploit the XML external entity processing vulnerability. Avoid using the DBConnections file parsing functionality until the issue is resolved.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2023-06848
CVE-2022-43512
ZDI-23-1041

Affected Products

Vbase Automation Base