CVE Vulnerabilities

CVE-2023-2140

Server-Side Request Forgery (SSRF)

Published: Apr 21, 2023 | Modified: May 09, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022

could allow an unauthenticated attacker to issue requests to arbitrary hosts on behalf of the server running the DELMIA Apriso application.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Delmia_apriso 3ds 2017 (including) 2022 (including)

References