First published: Wed Oct 16 2024(Updated: )
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
Credit: security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Application Automation Tools | <=24.1.0 |
Upgrade to version 24.2 or above of OpenText Application Automation Tools addresses this vulnerability:
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4690 is classified as a high-severity vulnerability due to its potential for DTD injection.
To fix CVE-2024-4690, upgrade OpenText Application Automation Tools to version 24.1.1 or later.
DTD Injection is a vulnerability that allows an attacker to inject malicious DTDs into an XML document, potentially leading to data exposure.
CVE-2024-4690 affects OpenText Application Automation Tools version 24.1.0 and below.
There is no specific workaround for CVE-2024-4690; updating to a fixed version is recommended.