Impact
Datavane TIS 5.0.0 contains an XML external entity (XXE) injection flaw that allows authenticated attackers to send a crafted taskScript XML to the doEditWorkflow endpoint. The server parses XML with an unhardened DocumentBuilderFactory that permits external entity references and DTD loading, enabling server‑side request forgery and out‑of‑band exfiltration of configuration files and database credentials (CWE‑611).
Affected Systems
The vulnerability is present in Datavane TIS version 5.0.0. No other vendors or product versions are currently listed as affected. Administrators should ensure they are not running this version and consult Datavane for updates.
Risk and Exploitability
The issue scores a CVSS of 8.3, indicating high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so the exploitation likelihood is uncertain, but the flaw requires only an authenticated session. Attackers can potentially perform SSRF and read local files if the endpoint is reachable, making prompt remediation a priority.
OpenCVE Enrichment