Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-29801

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

CVE
#vulnerability#pdf

%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 646.963 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 574.928 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 179.407 null] >> endobj 6 0 obj << /D [2 0 R /XYZ 70.866 72.503 null] >> endobj 7 0 obj << /D [8 0 R /XYZ 85.039 258.973 null] >> endobj 9 0 obj << /D [10 0 R /XYZ 70.866 576.314 null] >> endobj 11 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 12 0 R /Type /Page /Resources 13 0 R /Parent 14 0 R /Annots [15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 15 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 475.456 446.757 486.873] >> endobj 16 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 450.056 433.497 462.733] >> endobj 17 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 421.46 446.757 432.877] >> endobj 18 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 396.06 433.497 408.738] >> endobj 19 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [458.38 369.358 518.276 378.882] >> endobj 21 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 319.111 446.757 330.528] >> endobj 22 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 293.711 433.497 306.389] >> endobj 23 0 obj << /A << /S /URI /Type /Action /URI (https://support.sw.siemens.com/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 265.116 446.757 276.533] >> endobj 24 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 239.716 433.497 252.393] >> endobj 25 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [458.38 213.013 518.276 222.537] >> endobj 27 0 obj << /A << /S /GoTo /D (section*.2) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [386.143 89.32 524.579 100.857] >> endobj 28 0 obj << /A << /S /GoTo /D (section*.4) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [147.498 71.507 309.548 82.924] >> endobj 13 0 obj << /ProcSet [/PDF /Text] /Font << /F50 29 0 R /F47 30 0 R >> >> endobj 12 0 obj << /Filter /FlateDecode /Length 2363 >> stream x��ZIs�F��W�6`U��}q�Ȳlje;"�x��&!�c������y��������h�����8��p����ы�\EIe4��FZ�H�Q�x}�G�t�.���*���: ��g��~�x�}Vd0�p���f�x�c�Mד���|O��=:��C8"w ��&����h ��aČ�nݓ�� �g0�G��ߏp��6hZ�k�����(�!��#�C�+UW�0�H4:*m��/�!��,.hh�v�؇�}H�_�]���)��@�x=_�y�u6����h BG|?5rĄꐄ ���� ievIb� Λ�̖���f�W��,�2���hi�d{l �&�I�,�܉���[@R $��@�1O���!o>�$�,[z̽J��%�SsSL��!�v <$�H����(�;��K(B�{K��N�y|�/$� X��D������.G#��w����i�,� ()b�tg����B��;�%�QD�&xѦ�j)(��R�gg�����ŷ�2�;Fx�d@��!Π��E���xV�kru5�&N’e:�3U���Og����/�&�2���e�®�]�(8+��/X�O�N�w’��Cg5j4&� K/Ê��e2�k |����V[�X W�sܮAfM�͕ %|�i�c��o�y]h������ON �|"���D�O��dR���-��eP0�C�/�׷�^��:.���{a ‘aÂNH ���.m�$n��<��NGnz�P~r6�i�ހ�]�g`bk@;�4��Y��r�� M�00 ?����K6�ʛ01�ܔkȘ:R � �!;x��K9���Ѐ�Y���t������sW���.m%ִ� �ً��p_��� ��N��$[/+/_�f�yE"حb!(i�5� �b�v �S�17I5��ʟ�/�?�ۺun{㴔�扏����}�Hp�j�3�(�#Aai:��ׯOOƧ�:� j�U��+C�,v�"B�b^��ż%���ϭ�>��8�:$0 1�O#]܃��S &�2���S �T/�)e��}G!��.�-1.T��чw��w�� 4�jW4��F�Mk%��i �$^��<�����}<��SQ~m͜7:���ԗ���ҜT��4�����k͑r l�7 ��1tHlU@w-��w�B(YN��H�� Q�޶O�$�O�� a��B������9�2����%����� �v;X\p��u{���P�`AwKu�1��f�����x�t8��q�db� �9k�݂��!�j���|~_��s�>���=H��B�ʁ�_T%0�J�&c��m+�v����Zո�U�VrS�����z��B=� [w��~ ��Yʘ ���Ǎ: �C�� J�Z��l�"���N��*���"���HA6�2$���ИKf��Te0�-ɡ��[a� ���V���x+�@ƅm�x/���0�[,�A������*C�I� ��y���{��u��qZ��#����:��)t�������܂��W� �}iX�r���프+����2 v&�����w߭��>]$���]�X�\��"����  ���z�ˬ�j��_��L��W_!����\V� 5;�fG@�3<�,�H S�� �8 ��ۣ��� ��X��[O�7j8H�����F�8+B��7@(���P��;kZ�/�z!��F��gN����U�}��x��jIP� �=IX�s�9H�J5td�?�x�Ĉ�’{�{-V`i��>�{)`�S!���Rx0O��>��m� J�5�}i艱_��!�jJ%x�����}�~}m�QW�U���E��U5���TՏ�z +��e�ۏ�� ��v�y,��ϙ|��@"�*�?�n��o�~[�����]5 C��Ľ�jRU���cS � ���tn���T؇s�W�0�n�[RL4�>{;~��x`pl7�F�GCk�, ���’ Tu��)��5����0�[��y6 <��{�0��KW�� ُ7�_u���I�G�uQf ��6Y�wW+��y���!�j�j��y:]O���& �ف��˭"���ڀn�L��_(ͧ>��?��E���:���y�Uǘ�j��V�>�TG���$ �&�LҢh�����̃r���e�e:w�v N9��Ֆ�$�h�?V�’|=’���*#��k�’�’��9�=�榃B��>�ʔ���D���x���5r�=�WO�evc��j�9dy����ߤ�!���GMϷZc�)�:W� ��+���,�۪���/���_� �_m bJ(�?�.N�����ٕ��6�� v�� endstream endobj 31 0 obj << /D [2 0 R /XYZ 69.866 808.885 null] >> endobj 30 0 obj << /Subtype /Type1 /FirstChar 2 /Type /Font /BaseFont /EUXZIT+NimbusSanL-Regu /FontDescriptor 32 0 R /Encoding 33 0 R /LastChar 169 /Widths 34 0 R >> endobj 29 0 obj << /Subtype /Type1 /FirstChar 45 /Type /Font /BaseFont /BFSBBM+NimbusSanL-Bold /FontDescriptor 35 0 R /Encoding 33 0 R /LastChar 117 /Widths 36 0 R >> endobj 37 0 obj << /D [2 0 R /XYZ 70.866 524.28 null] >> endobj 20 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 354.02 372.108 366.697] >> endobj 26 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 197.676 372.108 210.353] >> endobj 14 0 obj << /Kids [2 0 R 8 0 R 10 0 R] /Type /Pages /Count 3 >> endobj 38 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/cert/operational-guidelines-industrial-security) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [164.798 698.869 487.754 710.406] >> endobj 39 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/industrialsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [406.699 669.101 525.406 680.518] >> endobj 40 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [131.954 522.934 248.203 534.471] >> endobj 41 0 obj << /A << /S /URI /Type /Action /URI (https://cwe.mitre.org/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [69.87 433.271 163.926 444.807] >> endobj 42 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 345.564 507.302 359.512] >> endobj 43 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 234.067 510.543 248.014] >> endobj 44 0 obj << /ProcSet [/PDF /Text] /Font << /F50 29 0 R /F47 30 0 R >> >> endobj 8 0 obj << /Contents 45 0 R /Type /Page /Resources 44 0 R /Parent 14 0 R /Annots [38 0 R 39 0 R 46 0 R 40 0 R 41 0 R 42 0 R 43 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 45 0 obj << /Filter /FlateDecode /Length 2525 >> stream xڭY�s�H~�_��JUAh4�5�9�Ͳ��>��\%���1�EH�濿���1�����QOwO�����칽�W��W�_���zao�؋\’�^����7_��Z�L�tQ�}/���N��/+���z�U%�k�����^�ߔ�mZ��Sf��?�_��W��`����I�KWW_�p{ ���:RŽ3s�������7��ו�N�B�� t�s��q�x��D%���X�%P�c ����xz}s��|�s������f�}���8q|�n��C�g���t2�� �c� !��v�υ�:k:�R�h�t<���i|���]��V�B�����Id�^���z��@!(Z��k�G)"+��Rzc �JrT��>�9�V:��mC������zS˜’otZ�`p��uI����uZ�Ch�~��U�B?آ4�U筅�jy�`]E�8[�\�΃p)I޽d�֛o%kXq͞$�&�J�OI�U� �q`��A �, f���r��!Ҫ�XX�)�̌d/L�W/ht2’�. �3�~G�&��ׁe �h<܏�{d)\Ӳ���7 ��0�Y��lp7+�<���!��S�}V� (\n��γB���I|��-��$��C�縱GuqUI��Jܡ�"/���T,��,Y���U�k_Ʈ�T��j8���؁�����; ����RY���P���j�!z�} au`%�C� .��wR�VR��+�A��C�C�:M��#�v���)� ί��gc+7ʱ�Yk�*��J tn�����G8#��g8X,�fw��R)���r1��Hs�n�v6EM’4�;����&�黦+�a���Ǥ>��~(��]Ǔ������{�m���’�7ڪ� �*�sd�����������%��k���/Q�����k��|�F��=v�� ^V���7n���3�m� K’�P���|�V[�\IƵ���$��K� Y$�:��V��앉���$�N��8TN�Ԍ������5�����맄5���թ� ��*㶴��:�%���ņ�+n�f0ݔ;��-���s����ܦ�q(bk�-���]?mt�+Q�m ) �<�3S��I2������\�ı#� R=6#=I����)����i:Ď��K�5�C�H���P���l��� ��>�n�g�ɯ�ю��M� � s���ǥ

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda