First published: Wed Oct 16 2024(Updated: )
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Credit: security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Application Automation Tools | <=24.1.0 |
Upgrade to version 24.2 or above of OpenText Application Automation Tools addresses this vulnerability:
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4189 is classified as a high severity vulnerability due to its potential for DTD injection.
To fix CVE-2024-4189, upgrade to a version of OpenText Application Automation Tools later than 24.1.0.
CVE-2024-4189 can lead to unauthorized access and potentially allow attackers to execute commands on the server.
CVE-2024-4189 affects all versions of OpenText Application Automation Tools up to and including 24.1.0.
In the context of CVE-2024-4189, DTD Injection refers to the manipulation of XML data to execute malicious commands by exploiting improper XML parsing.