CVE-2023-22377
Published Feb 15, 2023
Last updated 2 years ago
Overview
- Description
- Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain condition by reading a specially crafted XML file.
- Source
- vultures@jpcert.or.jp
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.4
- Impact score
- 5.2
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- CWE-611
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fujitsu:tsclinical_define.xml_generator:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CD969AE-0F5A-47AA-AEC5-D09799E4CB84", "versionEndIncluding": "1.4.0", "versionStartIncluding": "1.0.0" }, { "criteria": "cpe:2.3:a:fujitsu:tsclinical_metadata_desktop_tools:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86E0D282-DB0B-4D98-903F-D491E88CE0A5", "versionEndExcluding": "1.1.1", "versionStartIncluding": "1.0.3" } ], "operator": "OR" } ] } ]