SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-8789 SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T00:25:38.048Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-21517

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-01T21:15:14.350

Modified: 2024-11-21T05:48:30.953

Link: CVE-2021-21517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.