← Back

CVE-2021-28973

nvd nist
Published: Apr 13, 2021Modified: Jun 17, 2026

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD

Description

The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.

Affected (1)

Products: Perforce: Helix Alm
1 product
Helix Alm
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2020.3.1 build_22

Timeline

No history available yet.