Impact
This vulnerability allows an attacker to leverage default passwords automatically assigned to accounts created through XML import in Tuleap Enterprise Edition. The weakness is identified as CWE-1393, which involves the use of a default or negligible password, enabling credential compromise. If an attacker can obtain the default credentials, they can log in to the affected accounts and potentially access or modify sensitive data, increasing both confidentiality and integrity risk.
Affected Systems
Dassault Systèmes' Tuleap Enterprise Edition is affected from version 17.0 through 17.5. Any installation within this version range that performs XML import operations will expose new user accounts with a default password. Older or newer releases are not impacted according to the current CNA data.
Risk and Exploitability
The CVSS base score of 7.7 indicates a high severity. EPSS is not reported, and the vulnerability is not listed in CISA KEV, suggesting it is not widely exploited yet. The likely attack vector is the XML import process itself, where an attacker who can either supply an import file or who knows the default password can bypass authentication. Successful exploitation results in unauthorized access to user accounts created by the import, potentially giving an attacker full privileges within the Tuleap instance.
OpenCVE Enrichment