SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.
2021-03-01T21:15:14.350
2024-11-21T05:48:30.953
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dell | emc_srs_policy_manager | 6.6 | Yes |
Application | dell | emc_srs_policy_manager | 6.8.3 | Yes |
Application | dell | emc_srs_policy_manager | 6.9.0 | Yes |