Vulnerability Description
The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Perforce | Helix Alm | 2020.3.1 |
Related Weaknesses (CWE)
References
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-01_CSNC-2021ExploitThird Party Advisory
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-01_CSNC-2021ExploitThird Party Advisory
FAQ
What is CVE-2021-28973?
CVE-2021-28973 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE at...
How severe is CVE-2021-28973?
CVE-2021-28973 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28973?
Check the references section above for vendor advisories and patch information. Affected products include: Perforce Helix Alm.