PT-2024-19063 · Unknown · Electronic Deliverables Creation Support Tool

Toyama Taku

·

Published

2024-01-23

·

Updated

2024-09-10

·

CVE-2024-21796

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Electronic Deliverables Creation Support Tool (Construction Edition) versions prior to 1.0.4 Electronic Deliverables Creation Support Tool (Design & Survey Edition) versions prior to 1.0.4
Description The issue is related to the improper restriction of XML external entity references (XXE) in the affected software. By processing a specially crafted XML file, an attacker may be able to read arbitrary files on the system.
Recommendations For Electronic Deliverables Creation Support Tool (Construction Edition) versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. For Electronic Deliverables Creation Support Tool (Design & Survey Edition) versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting the processing of XML files from untrusted sources until a patch is available.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2024-21796

Affected Products

Electronic Deliverables Creation Support Tool