Vulnerabilities > CVE-2019-20153 - XXE vulnerability in Determine Contract Lifecycle Management 5.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote attackers to read arbitrary files (including configuration files containing administrative credentials).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |