CVE Vulnerabilities

CVE-2022-3340

Improper Restriction of XML External Entity Reference

Published: Nov 04, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Intrusion_prevention_system_manager Trellix * 10.1 (excluding)
Intrusion_prevention_system_manager Trellix 10.1 (including) 10.1 (including)
Intrusion_prevention_system_manager Trellix 10.1-minor8 (including) 10.1-minor8 (including)

Potential Mitigations

References