Vulnerabilities > CVE-2021-42537 - XXE vulnerability in Visam Vbase Web-Remote 11.6.0.6

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
visam
CWE-611

Summary

VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Vulnerable Configurations

Part Description Count
Application
Visam
1