vendor:
RSA Enterprise Compromise Assessment Tool (ECAT)
by:
Samandeep Singh
5,5
CVSS
MEDIUM
XML External Entity Injection
611
CWE
Product Name: RSA Enterprise Compromise Assessment Tool (ECAT)
Affected Version From: 4.1.0.1
Affected Version To: 4.1.2.0
Patch Exists: YES
Related CWE: -
CPE: a:rsa:enterprise_compromise_assessment_tool
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
XML External Entity Injection (XXE)
The used XML parser is resolving external XML entities which allows attackers to rea files from the local filesystem and to perform port scans.
Mitigation:
SEC Consult recommends not to use the product until a thorough security review has been performed by security professionals and all identified issues have been resolved.