Unrated severityNVD Advisory· Published Aug 10, 2021· Updated Aug 4, 2024
CVE-2021-37425
CVE-2021-37425
Description
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Altova/MobileTogether Serverdescription
- Range: <7.3 SP1
Patches
Vulnerability mechanics
References
4- seclists.org/fulldisclosure/2021/Aug/12mitrex_refsource_MISC
- www.altova.com/mobiletogethermitrex_refsource_MISC
- www.redteam-pentesting.de/advisories/rt-sa-2021-002mitrex_refsource_MISC
- www.redteam-pentesting.de/en/advisories/-advisories-publicised-vulnerability-analysesmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.