First published: Wed Jul 20 2022(Updated: )
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Digiwin Business Process Management | <5.8.8.1 |
Update version to 5.8.8.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32458 is considered a high severity vulnerability as it allows unauthenticated attackers to access sensitive system files.
To mitigate CVE-2022-32458, ensure proper validation of XML input and upgrade to a version of Digiwin BPM that is not vulnerable.
CVE-2022-32458 facilitates an XML External Entity Injection (XXE) attack, allowing attackers to manipulate XML data.
Users of Digiwin Business Process Management prior to version 5.8.8.1 are impacted by CVE-2022-32458.
Yes, CVE-2022-32458 can be exploited remotely by an unauthenticated attacker.