Описание
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
Ссылки
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.0 (включая) до 7.3 (исключая)
Одно из
cpe:2.3:a:altova:mobiletogether_server:*:*:*:*:*:*:*:*
cpe:2.3:a:altova:mobiletogether_server:7.3:-:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.08684
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
github
больше 3 лет назад
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
EPSS
Процентиль: 92%
0.08684
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-611