CVE-2021-33581
Last modified
CVE-2021-33581 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Softwareag | Mashzone Nextgen | <= 10.7 |
References
- https://github.com/blackarrowsec/advisories/tree/master/2021/CVE-2021-33581Third Party Advisory
- https://www.softwareag.com/corporate/products/az/mashzone_nextgen/defaultProduct, Vendor Advisory
- https://github.com/blackarrowsec/advisories/tree/master/2021/CVE-2021-33581Third Party Advisory
- https://www.softwareag.com/corporate/products/az/mashzone_nextgen/defaultProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33581?
How severe is CVE-2021-33581?
How do I fix CVE-2021-33581?
Are you affected by CVE-2021-33581?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
