CVE-2025-6438
Severity CVSS v4.0:
MEDIUM
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
11/07/2025
Last modified:
03/11/2025
Description
A<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could<br />
cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access<br />
when the server is accessed via the network using an application account.
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM
Base Score 3.x
6.80
Severity 3.x
MEDIUM



