CVE-2021-37425
10.08.2021, 22:15
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.Enginsight
| Vendor | Product | Version |
|---|---|---|
| altova | mobiletogether_server | 7.0 ≤ 𝑥 < 7.3 |
| altova | mobiletogether_server | 7.3 |
𝑥
= Vulnerable software versions
References