TROYANOSYVIRUS
Back to CVEs

CVE-2019-20153

MEDIUM
4.9

Description

An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote attackers to read arbitrary files (including configuration files containing administrative credentials).

CVE Details

CVSS v3.1 Score4.9
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published1/5/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

determine:contract_lifecycle_management

Weaknesses (CWE)

CWE-611

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.