Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
History

Fri, 18 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-01-24T01:32:47.520Z

Updated: 2024-10-18T15:48:12.036Z

Reserved: 2024-01-12T07:58:22.276Z

Link: CVE-2024-22380

cve-icon Vulnrichment

Updated: 2024-08-01T22:43:34.703Z

cve-icon NVD

Status : Analyzed

Published: 2024-01-24T02:15:07.233

Modified: 2024-01-30T22:14:24.967

Link: CVE-2024-22380

cve-icon Redhat

No data.