PT-2026-72029 · Datavane+1 · Tis
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Datavane TIS version 5.0.0
Description
An XML external entity (XXE) injection exists when the software processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Authenticated attackers can exploit this by supplying a crafted
taskScript payload to the 'doEditWorkflow' endpoint. This allows for server-side request forgery (SSRF), where the server is forced to make outbound HTTP requests to attacker-controlled infrastructure, and out-of-band file exfiltration of local files readable by the TIS process user, such as configuration files and Derby database credentials.Recommendations
Update Datavane TIS version 5.0.0 to a version where the DocumentBuilderFactory is hardened to disable external entities and DTD loading.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tis