ZDI-23-1041: VBASE VISAM Automation Base DBConnections File Parsing XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of VBASE VISAM Automation Base. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1041?
The severity of ZDI-23-1041 is classified as medium due to its potential to disclose sensitive information.
How do I fix ZDI-23-1041?
To mitigate ZDI-23-1041, users should apply the latest security patches provided by VBASE for the VISAM Automation Base.
What kind of attack is ZDI-23-1041 associated with?
ZDI-23-1041 is associated with remote information disclosure attacks that require user interaction.
Which software is affected by ZDI-23-1041?
ZDI-23-1041 affects VBASE VISAM Automation Base installations.
Is user interaction necessary for ZDI-23-1041 exploitation?
Yes, user interaction is required for ZDI-23-1041, as the target must visit a malicious page or open a malicious file.