Filtered by vendor Digiwin Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-32458 1 Digiwin 1 Business Process Management 2022-09-14 7.5 High
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files.
CVE-2022-32457 1 Digiwin 1 Business Process Management 2022-09-14 5.3 Medium
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.
CVE-2022-32456 1 Digiwin 1 Business Process Management 2022-09-14 9.8 Critical
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.