First published: Tue Apr 11 2023(Updated: )
A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Polarion ALM | <2304.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28828 is classified as a medium severity vulnerability due to the potential for unauthorized access to server files.
To fix CVE-2023-28828, upgrade Polarion ALM to version 22R2 or later.
CVE-2023-28828 can enable attackers to exploit XML External Entity Injection to read sensitive files from the application server.
All versions of Polarion ALM earlier than version 22R2 are affected by CVE-2023-28828.
There are no known workarounds for CVE-2023-28828 other than upgrading to a secure version.