XXE Vulnerability in Perforce Helix ALM Administration Console
CVE-2021-28973

4.9MEDIUM

Key Information:

Vendor

Perforce

Status
Vendor
CVE Published:
13 April 2021

What is CVE-2021-28973?

The XML Import feature in the Administration console of Perforce Helix ALM 2020.3.1 Build 22 is susceptible to XXE attacks due to unsafe configurations in processing XML input. This flaw allows attackers to inject malicious XML content that can lead to unauthorized data exposure or system compromise.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.