Lucene search

K
jvnJapan Vulnerability NotesJVN:73178249
HistoryApr 19, 2023 - 12:00 a.m.

JVN#73178249: Improper restriction of XML external entity references (XXE) in Shinseiyo Sogo Soft

2023-04-1900:00:00
Japan Vulnerability Notes
jvn.jp
9
xml external entity (xxe)
shinseiyo sogo soft
ministry of justice
arbitrary files
software update
cwe-611

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

60.8%

Shinseiyo Sogo Soft provided by The Ministry of Justice improperly restricts XML external entity references (XXE) (CWE-611).

Impact

By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer

Products Affected

  • Shinseiyo Sogo Soft (7.9A) and earlier

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

60.8%

Related for JVN:73178249