← Back to CVE List

CVE-2021-21517

Published: 2021-03-01T21:15Z
Last Modified: 2024-11-21T05:48Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt