CVE-2021-21517
01.03.2021, 21:15
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| dell | emc_srs_policy_manager | 6.6 |
| dell | emc_srs_policy_manager | 6.8.3 |
| dell | emc_srs_policy_manager | 6.9.0 |
𝑥
= Vulnerable software versions
References