[Japanese]

JVNDB-2024-000009

Improper restriction of XML external entity references (XXE) in Electronic Deliverables Creation Support Tool provided by Ministry of Defense

Overview

Electronic Deliverables Creation Support Tool provided by Ministry of Defense improperly restricts XML external entity references (XXE) (CWE-611).

Toyama Taku of NEC Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 2.5 (Low) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
CVSS V2 Severity:
Base Metrics 1.2 (Low) [IPA Score]
  • Access Vector: Local
  • Access Complexity: High
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


Ministry of Defense
  • Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4
  • Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4

Impact

Processing a specially crafted XML file may lead to exposure of internal files on the system.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

Ministry of Defense
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2024-21796
References

  1. JVN : JVN#40049211
  2. National Vulnerability Database (NVD) : CVE-2024-21796
Revision History

  • [2024/01/23]
      Web page was published
  • [2024/03/13]
      References : Content was added