Vulnerabilities > CVE-2021-45096 - XXE vulnerability in Knime Analytics Platform

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
knime
CWE-611

Summary

KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (.knwf), aka AP-17730.

Vulnerable Configurations

Part Description Count
Application
Knime
49