8.8
CVE-2022-25628
- EPSS 0.21%
- Veröffentlicht 16.12.2022 16:15:21
- Zuletzt bearbeitet 18.04.2025 14:15:18
- Quelle secure@symantec.com
- CVE-Watchlists
- Unerledigt
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Symantec Identity Governance And Administration Version14.3
Broadcom ≫ Symantec Identity Governance And Administration Version14.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.434 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.