Reflected Cross-Site Scripting in Teamcenter Active Workspace by Siemens
CVE-2021-33710
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 13 July 2021
Summary
A reflected cross-site scripting (XSS) vulnerability has been detected in the web interface of Teamcenter Active Workspace. This flaw affects several versions of the product, allowing attackers to inject malicious JavaScript code via specially crafted links. Users tricked into clicking these links may inadvertently execute harmful scripts in their browsers, potentially leading to unauthorized actions and data exposure. It's essential for organizations using affected versions to apply security updates and implement safeguards to mitigate this risk.
Affected Version(s)
Teamcenter Active Workspace V4 All versions < V4.3.9
Teamcenter Active Workspace V5.0 All versions < V5.0.7
Teamcenter Active Workspace V5.1 All versions < V5.1.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved