A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022
could allow an unauthenticated attacker to issue requests to arbitrary hosts on behalf of the server running the DELMIA Apriso application.
References
Link | Resource |
---|---|
https://www.3ds.com/vulnerability/advisories | Vendor Advisory |
Configurations
History
09 May 2023, 00:56
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:3ds:delmia_apriso:*:*:*:*:*:*:*:* | |
References | (MISC) https://www.3ds.com/vulnerability/advisories - Vendor Advisory | |
CWE | CWE-918 |
21 Apr 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-21 16:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-2140
Mitre link : CVE-2023-2140
CVE.ORG link : CVE-2023-2140
JSON object : View
Products Affected
3ds
- delmia_apriso
CWE
CWE-918
Server-Side Request Forgery (SSRF)