CVE-2021-33208

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
30/03/2022
Last modified:
05/04/2022

Description

The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:softwareag:mashzone_nextgen:*:*:*:*:*:*:*:* 10.7 (including)