Aria Automation contains a Missing Access Control vulnerability.
An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.
A flaw was found in FasterXML Jackson Databind which did not have entity expansion secured properly making it vulnerable to XML external entity (XXE). This vulnerability is similar to CVE-2019-10172. The primary threat from this flaw is data integrity.