CVE-2021-22498

XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity Injection.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
microfocusCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
microfocusapplication_lifecycle_management
12.50 ≤
𝑥
≤ 12.60
microfocusapplication_lifecycle_management
15.0.0 ≤
𝑥
≤ 15.0.1
microfocusapplication_lifecycle_management
12.60:patch1
microfocusapplication_lifecycle_management
12.60:patch2
microfocusapplication_lifecycle_management
12.60:patch3
microfocusapplication_lifecycle_management
12.60:patch4
microfocusapplication_lifecycle_management
12.60:patch5
microfocusapplication_lifecycle_management
15.0.1:patch1
microfocusapplication_lifecycle_management
15.0.1:patch2
microfocusapplication_lifecycle_management
15.5
𝑥
= Vulnerable software versions