High severity7.5NVD Advisory· Published Mar 18, 2022· Updated Jun 17, 2026
CVE-2021-45968
CVE-2021-45968
Description
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:jivesoftware:jive:-:*:*:*:*:*:*:*
cpe:2.3:a:pascom:cloud_phone_system:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:pascom:cloud_phone_system:*:*:*:*:*:*:*:*range: <=7.19
- (no CPE)range: <7.20.x
- JIve/XMPP Serverdescription
Patches
Vulnerability mechanics
References
5- kerbit.io/research/read/blog/4nvdExploitThird Party Advisory
- tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.htmlnvdExploitThird Party Advisory
- jivesoftware.com/platform/nvdProductThird Party Advisory
- www.pascom.net/doc/en/release-notes/nvdRelease NotesVendor Advisory
- www.pascom.net/doc/en/release-notes/pascom19/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.