← Back

CVE-2021-28973

nvd nist
Published: Apr 13, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.

Affected (1)

Products: Perforce: Helix Alm
1 product
Helix Alm
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2020.3.1 build_22

Timeline

No history available yet.