Unrated severityNVD Advisory· Published Sep 29, 2025· Updated Sep 29, 2025
CVE-2025-48006
CVE-2025-48006
Description
Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.
Affected products
2- Range: <=4.4
- Saison Technology Co.,Ltd./DataSpider Servistav5Range: 4.4 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.