CVE-2023-28828 MEDIUM

CVE-2023-28828

Vendor Siemens
Product Polarion ALM
Weakness CWE-611 · XXE
Published April 11, 2023
Last update February 7, 2025

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

What the vulnerability does

01Description

A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

Key dates

02Disclosure timeline

April 11, 2023 CVE published
February 7, 2025 Record updated