Impact
Improper restriction of XML external entity references in Hitachi Cosminexus Component Container enables attackers to pass crafted XML that references external entities. This flaw can allow the application to read arbitrary files, retrieve data from remote resources, or potentially trigger code execution if the external entities are exploited in a more complex environment. The impact is primarily the disclosure of confidential data, but in some configurations could facilitate further attack stages.
Affected Systems
Hitachi Cosminexus Component Container versions 11‑70‑01 to 11‑70‑02, 11‑60‑01 to 11‑60‑02, 11‑50‑01 to 11‑50‑03, 11‑40‑01 to 11‑40‑03, 11‑30‑01 to 11‑30‑08, 11‑20‑01 to 11‑20‑09, 11‑10‑01 to 11‑10‑11, 11‑00‑01 to 11‑00‑12, 09‑87‑01 to 09‑87‑09, 09‑80‑01 to 09‑80‑04, 09‑70‑01 to 09‑70‑27, 09‑50‑01 to 09‑50‑22, and 09‑00‑01 to 09‑00‑18.
Risk and Exploitability
The CVSS score of 7.4 classifies this as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is inferred to be through any interface that accepts XML input—such as web services, configuration files, or management consoles—allowing an adversary to inject malicious XML. Exploitation would require authentication or access to the vulnerable component; therefore, internal attackers or those who can send crafted XML are the most realistic threat actors.
OpenCVE Enrichment