CVE-2021-42537
Summary
| CVE | CVE-2021-42537 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-27 21:15:00 UTC |
| Updated | 2022-08-05 14:47:00 UTC |
| Description | VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Visam | Vbase Web-remote | 11.6.0.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VISAM VBASE Editor | CISA | CONFIRM | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Michael Heinzl reported these vulnerabilities to CISA.
Legacy QID Mappings
- 590595 VISAM VBASE Editor Multiple Vulnerabilities (ICSA-21-308-01)