CVE-2021-37425
10.08.2021, 22:15
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.Enginsight
Vendor | Product | Version |
---|---|---|
altova | mobiletogether_server | 7.0 ≤ 𝑥 < 7.3 |
altova | mobiletogether_server | 7.3 |
𝑥
= Vulnerable software versions
References