Vulnerabilities (CVE)

Filtered by vendor Altova Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37425 1 Altova 1 Mobiletogether Server 2021-08-18 6.4 MEDIUM 9.1 CRITICAL
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.