CVE-2022-25628: XEE
Published Dec 16, 2022
·Updated
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
Affected Software
2 affected components
Broadcom Symantec Identity Governance And Administration=14.3
Broadcom Symantec Identity Governance And Administration=14.4
Event History
Dec 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-25628?
CVE-2022-25628 has a medium severity rating due to its potential to allow XML eXternal Entity injection.
2
How do I fix CVE-2022-25628?
To fix CVE-2022-25628, update to Symantec Identity Manager version 14.4 or later.
3
What systems are affected by CVE-2022-25628?
CVE-2022-25628 affects Symantec Identity Governance and Administration versions 14.3 and 14.4.
4
What type of attack can CVE-2022-25628 facilitate?
CVE-2022-25628 can facilitate XML eXternal Entity injection attacks, potentially compromising sensitive data.
5
Who can exploit CVE-2022-25628?
An authenticated user can exploit CVE-2022-25628 in the Management Console of Symantec Identity Manager.