VYPR
Unrated severityNVD Advisory· Published Sep 29, 2025· Updated Sep 29, 2025

CVE-2025-48006

CVE-2025-48006

Description

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.

Affected products

2
  • Range: <=4.4
  • Saison Technology Co.,Ltd./DataSpider Servistav5
    Range: 4.4 and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.