Vulnerabilities > Altova

DATE CVE VULNERABILITY TITLE RISK
2021-08-10 CVE-2021-37425 XXE vulnerability in Altova Mobiletogether Server 7.0/7.3
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
network
low complexity
altova CWE-611
critical
9.1
2021-08-10 CVE-2021-38490 XML Entity Expansion vulnerability in Altova Mobiletogether Server 7.0/7.3
Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.
network
low complexity
altova CWE-776
7.5