First published: Wed Feb 15 2023(Updated: )
Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain condition by reading a specially crafted XML file.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Fujitsu Tsclinical Define.xml Generator | >=1.0.0<=1.4.0 | |
Fujitsu Tsclinical Metadata Desktop Tools | >=1.0.3<1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22377 is an improper restriction of XML external entity reference (XXE) vulnerability that exists in tsClinical Define.xml Generator and tsClinical Metadata Desktop Tools.
The severity of CVE-2023-22377 is high, with a CVSS score of 7.4.
CVE-2023-22377 affects tsClinical Define.xml Generator versions 1.0.0 to 1.4.0 and tsClinical Metadata Desktop Tools versions 1.0.3 to 1.1.0.
An attacker can exploit CVE-2023-22377 to obtain an arbitrary file by exploiting the improper restriction of XML external entity reference vulnerability.
Yes, you can find more information about CVE-2023-22377 at the following references: [Link 1](https://github.com/tsClinical/tsc-desktop/security/advisories), [Link 2](https://jvn.jp/en/jp/JVN00712821/).