CVE-2023-22377
CVE-2023-22377
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.4EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
15 Feb 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain condition by reading a specially crafted XML file.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
FUJITSU LIMITED · tsClinical Define.xml Generator and tsClinical Metadata Desktop ToolsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →