Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-01-24T01:32:47.520Z
Updated: 2024-10-18T15:48:12.036Z
Reserved: 2024-01-12T07:58:22.276Z
Link: CVE-2024-22380
Vulnrichment
Updated: 2024-08-01T22:43:34.703Z
NVD
Status : Analyzed
Published: 2024-01-24T02:15:07.233
Modified: 2024-01-30T22:14:24.967
Link: CVE-2024-22380
Redhat
No data.