Impact
A Server‑Side Request Forgery vulnerability exists in PTC Windchill PDMLink and PTC FlexPLM that can be triggered by deserializing untrusted data. The flaw allows an attacker to craft a payload that forces the application to perform HTTP requests to arbitrary hosts, potentially exposing internal resources and sensitive services to unauthorized users.
Affected Systems
The affected products are PTC FlexPLM and PTC Windchill PDMLink. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 7.7 classifies the vulnerability as high severity. The EPSS score is not available, so the current exploitation probability is unclear; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is most likely via sending a maliciously crafted serialized object to the application, which is then processed and results in outbound requests to internal or external destinations.
OpenCVE Enrichment