Critical severity9.1NVD Advisory· Published Aug 10, 2021· Updated Jun 17, 2026
CVE-2021-37425
CVE-2021-37425
Description
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:altova:mobiletogether_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:altova:mobiletogether_server:*:*:*:*:*:*:*:*range: >=7.0,<7.3
- cpe:2.3:a:altova:mobiletogether_server:7.3:-:*:*:*:*:*:*
- (no CPE)range: <7.3 SP1
- Altova/MobileTogether Serverdescription
Patches
Vulnerability mechanics
References
4- seclists.org/fulldisclosure/2021/Aug/12nvdExploitMailing ListThird Party Advisory
- www.redteam-pentesting.de/advisories/rt-sa-2021-002nvdExploitThird Party Advisory
- www.altova.com/mobiletogethernvdVendor Advisory
- www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analysesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.