First published: Tue May 10 2022(Updated: )
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Teamcenter | <12.4.0.13 | |
Siemens Teamcenter | >=13.0<13.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-29801.
The severity of CVE-2022-29801 is high with a score of 7.5.
Teamcenter V12.4 (All versions < 12.4.0.13) and Teamcenter V13.0 (All versions < 13.0.0.9) are affected by CVE-2022-29801.
CVE-2022-29801 allows an attacker to view files on the application server filesystem.
To fix CVE-2022-29801, update Teamcenter to version 12.4.0.13 or higher for V12.4, and version 13.0.0.9 or higher for V13.0.