First published: Wed Mar 30 2022(Updated: )
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Softwareag Mashzone Nextgen | <=10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33581 is a SSRF vulnerability in MashZone NextGen that allows an attacker to interact with arbitrary TCP services.
CVE-2021-33581 works by abusing the feature to check the availability of a PPM connection in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.
CVE-2021-33581 has a severity rating of 7.2 (High).
MashZone NextGen versions up to and including 10.7 GA are affected by CVE-2021-33581.
To fix CVE-2021-33581, it is recommended to update to a version of MashZone NextGen that is not affected by the vulnerability.