Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41221

Опубликовано: 24 мая 2023
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft XML files that, when processed by the application, would cause a negative security impact such as data exfiltration or localized denial of service against the application instance and system of the user running it.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opentext:archive_center_administration:*:*:*:*:*:*:*:*
Версия до 21.2 (включая)

EPSS

Процентиль: 9%
0.00032
Низкий

7.1 High

CVSS3

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 7.1
github
больше 2 лет назад

The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft XML files that, when processed by the application, would cause a negative security impact such as data exfiltration or localized denial of service against the application instance and system of the user running it.

EPSS

Процентиль: 9%
0.00032
Низкий

7.1 High

CVSS3

Дефекты

CWE-611
CWE-611