Vulnerability Description
XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity Injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Application Lifecycle Management | >= 12.50, <= 12.60 |
Related Weaknesses (CWE)
References
- https://softwaresupport.softwaregrp.com/doc/KM03771781
- https://softwaresupport.softwaregrp.com/doc/KM03771781
FAQ
What is CVE-2021-22498?
CVE-2021-22498 is a vulnerability with a CVSS score of 8.1 (HIGH). XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and ear...
How severe is CVE-2021-22498?
CVE-2021-22498 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22498?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Application Lifecycle Management.