CVE-2019-20153

MEDIUM

Determine Contract Lifecycle Management v5.4 - Authenticated XML External Entity Injection via Definition Upload Feature

Title source: llm
STIX 2.1

Description

An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote attackers to read arbitrary files (including configuration files containing administrative credentials).

References (1)

Core 1

Scores

CVSS v3 4.9
EPSS 0.0120
EPSS Percentile 64.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
determine/contract_lifecycle_management 5.4
Published Jan 05, 2020
Tracked Since Feb 18, 2026