CVE-2021-22498

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
19/01/2021
Last modified:
07/11/2023

Description

XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity Injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microfocus:application_lifecycle_management:*:*:*:*:*:*:*:* 12.50 (including) 12.60 (including)
cpe:2.3:a:microfocus:application_lifecycle_management:*:*:*:*:*:*:*:* 15.0.0 (including) 15.0.1 (including)
cpe:2.3:a:microfocus:application_lifecycle_management:12.60:patch1:*:*:*:*:*:*
cpe:2.3:a:microfocus:application_lifecycle_management:12.60:patch2:*:*:*:*:*:*
cpe:2.3:a:microfocus:application_lifecycle_management:12.60:patch3:*:*:*:*:*:*
cpe:2.3:a:microfocus:application_lifecycle_management:12.60:patch4:*:*:*:*:*:*
cpe:2.3:a:microfocus:application_lifecycle_management:12.60:patch5:*:*:*:*:*:*
cpe:2.3:a:microfocus:application_lifecycle_management:15.0.1:patch1:*:*:*:*:*:*
cpe:2.3:a:microfocus:application_lifecycle_management:15.0.1:patch2:*:*:*:*:*:*
cpe:2.3:a:microfocus:application_lifecycle_management:15.5:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools