5.5
CVE-2020-26513
- EPSS 0.24%
- Veröffentlicht 07.12.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:19:56
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be abused for XML External Entity Attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intland ≫ Codebeamer Version >= 10.0.0 < 10.1.0
Intland ≫ Codebeamer Version10.1.0 Update-
Intland ≫ Codebeamer Version10.1.0 Updatesp1
Intland ≫ Codebeamer Version10.1.0 Updatesp2
Intland ≫ Codebeamer Version10.1.0 Updatesp3
Intland ≫ Codebeamer Version10.1.0 Updatesp4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.441 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.