{"api_version":"1","generated_at":"2026-06-03T21:14:06+00:00","cve":"CVE-2021-42537","urls":{"html":"https://cve.report/CVE-2021-42537","api":"https://cve.report/api/cve/CVE-2021-42537.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-42537","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-42537"},"summary":{"title":"CVE-2021-42537","description":"VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2022-07-27 21:15:00","updated_at":"2022-08-05 14:47:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01","name":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01","refsource":"CONFIRM","tags":[],"title":"VISAM VBASE Editor | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-42537","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42537","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Michael Heinzl reported these vulnerabilities to CISA.","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"42537","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"visam","cpe5":"vbase_web-remote","cpe6":"11.6.0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-42537","qid":"590595","title":"VISAM VBASE Editor Multiple Vulnerabilities (ICSA-21-308-01)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2021-42537","STATE":"PUBLIC","TITLE":"VISAM VBASE Editor  Improper Restriction of XML"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"VBASE Pro-RT/ Server-RT (Web Remote)","version":{"version_data":[{"version_affected":"=","version_value":"version 11.6.0.6"}]}}]},"vendor_name":"VISAM"}]}},"credit":[{"lang":"eng","value":"Michael Heinzl reported these vulnerabilities to CISA."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CVE-611"}]}]},"references":{"reference_data":[{"name":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01","refsource":"CONFIRM","url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01"}]},"solution":[{"lang":"eng","value":"VISAM recommends users update to VBASE v11.7.0.2 or later. Users may obtain a download link by submitting a request form.\n\nFor more information, please contact VISAM using the information provided on the company contact page."}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-07-27 21:15:00","lastModifiedDate":"2022-08-05 14:47:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:visam:vbase_web-remote:11.6.0.6:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"42537","Ordinal":"219022","Title":"CVE-2021-42537","CVE":"CVE-2021-42537","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"42537","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}