CVE-2021-28973

MEDIUM

Perforce Helix ALM 2020.3.1 Build 22 - XML External Entity Injection via XML Import

Title source: llm
STIX 2.1

Description

The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.

References (1)

Core 1

Scores

CVSS v3 4.9
EPSS 0.0089
EPSS Percentile 54.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
perforce/helix_alm 2020.3.1 build_22
Published Apr 13, 2021
Tracked Since Feb 18, 2026