Siemens Polarion
cpe:2.3:a:siemens:polarion:*:*:*:*:*:*:*
- >= V2404, < V2404.4
- V2310
A XML External Entity Injection (XXE) vulnerability has been identified in Siemens Polarion versions prior to V2410, specifically in the V2404 series before V2404.4. This vulnerability resides in the docx import feature, allowing authenticated remote attackers to read arbitrary data from the application server.
Exploitation of this vulnerability could lead to unauthorized data access on the application server.
Users are advised to update Polarion to V2410 or later. For Polarion V2404, patch releases can be applied.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.