CVE-2023-2140

A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue requests to arbitrary hosts on behalf of the server running the DELMIA Apriso application.
References
Link Resource
https://www.3ds.com/vulnerability/advisories Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:3ds:delmia_apriso:*:*:*:*:*:*:*:*

History

09 May 2023, 00:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:3ds:delmia_apriso:*:*:*:*:*:*:*:*
References (MISC) https://www.3ds.com/vulnerability/advisories - (MISC) https://www.3ds.com/vulnerability/advisories - Vendor Advisory
CWE CWE-918

21 Apr 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-21 16:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-2140

Mitre link : CVE-2023-2140

CVE.ORG link : CVE-2023-2140


JSON object : View

Products Affected

3ds

  • delmia_apriso
CWE
CWE-918

Server-Side Request Forgery (SSRF)