[Japanese]

JVNDB-2023-000096

Improper restriction of XML external entity references (XXE) in FD Application

Overview

FD Application provided by Ministry of Health, Labour and Welfare improperly restricts XML external entity references (XXE) (CWE-611).

Toyama Taku and Sakaki Ryutaro of NEC Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 2.5 (Low) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
CVSS V2 Severity:
Base Metrics 1.2 (Low) [IPA Score]
  • Access Vector: Local
  • Access Complexity: High
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


Ministry of Health, Labour and Welfare
  • FD Application Apr. 2022 Edition (Version 9.01) and earlier

Impact

By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.
The developer addressed the vulnerability in the following version:

  • FD Application Sep. 2023 Edition (Version 9.02)

Vendor Information

Ministry of Health, Labour and Welfare
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2023-42132
References

  1. JVN : JVN#39596244
Revision History

  • [2023/10/02]
      Web page was published