CVE-2021-21517
01.03.2021, 21:15
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.Enginsight
Vendor | Product | Version |
---|---|---|
dell | emc_srs_policy_manager | 6.6 |
dell | emc_srs_policy_manager | 6.8.3 |
dell | emc_srs_policy_manager | 6.9.0 |
𝑥
= Vulnerable software versions
References