First published: Tue Sep 14 2021(Updated: )
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (All versions < V13.1.0.5), Teamcenter V13.2 (All versions < 13.2.0.2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Teamcenter Visualization | >=12.4.0<12.4.0.8 | |
Siemens Teamcenter Visualization | >=13.0.0<13.0.0.7 | |
Siemens Teamcenter Visualization | >=13.1.0<13.1.0.5 | |
Siemens Teamcenter Visualization | >=13.2.0<13.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40356 has been classified as a medium severity vulnerability due to its potential for XML External Entity Injection.
To remediate CVE-2021-40356, it is recommended to upgrade to Teamcenter versions V12.4.0.8, V13.0.0.7, V13.1.0.5, or V13.2.0.2 or later.
CVE-2021-40356 affects Teamcenter versions V12.4 (all versions less than V12.4.0.8), V13.0 (all versions less than V13.0.0.7), V13.1 (all versions less than V13.1.0.5), and V13.2 (all versions less than V13.2.0.2).
CVE-2021-40356 is classified as an XML External Entity Injection (XXE) vulnerability.
Organizations using affected versions of Siemens Teamcenter Visualization software are impacted by CVE-2021-40356.