{"containers":{"cna":{"affected":[{"product":"VBASE Pro-RT/ Server-RT (Web Remote)","vendor":"VISAM","versions":[{"status":"affected","version":"version 11.6.0.6"}]}],"credits":[{"lang":"en","value":"Michael Heinzl reported these vulnerabilities to CISA."}],"descriptions":[{"lang":"en","value":"VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"description":"CVE-611","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2022-07-27T20:20:22.000Z","orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01"}],"solutions":[{"lang":"en","value":"VISAM recommends users update to VBASE v11.7.0.2 or later. Users may obtain a download link by submitting a request form.\n\nFor more information, please contact VISAM using the information provided on the company contact page."}],"source":{"discovery":"EXTERNAL"},"title":"VISAM VBASE Editor  Improper Restriction of XML","x_generator":{"engine":"Vulnogram 0.0.9"},"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2021-42537","STATE":"PUBLIC","TITLE":"VISAM VBASE Editor  Improper Restriction of XML"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"VBASE Pro-RT/ Server-RT (Web Remote)","version":{"version_data":[{"version_affected":"=","version_value":"version 11.6.0.6"}]}}]},"vendor_name":"VISAM"}]}},"credit":[{"lang":"eng","value":"Michael Heinzl reported these vulnerabilities to CISA."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CVE-611"}]}]},"references":{"reference_data":[{"name":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01","refsource":"CONFIRM","url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01"}]},"solution":[{"lang":"en","value":"VISAM recommends users update to VBASE v11.7.0.2 or later. Users may obtain a download link by submitting a request form.\n\nFor more information, please contact VISAM using the information provided on the company contact page."}],"source":{"discovery":"EXTERNAL"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T03:30:38.518Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-21-308-01"}]},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-611","lang":"en","description":"CWE-611 Improper Restriction of XML External Entity Reference"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-17T14:30:19.019563Z","id":"CVE-2021-42537","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-17T15:50:48.868Z"}}]},"cveMetadata":{"assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","assignerShortName":"icscert","cveId":"CVE-2021-42537","datePublished":"2022-07-27T20:20:22.000Z","dateReserved":"2021-10-15T00:00:00.000Z","dateUpdated":"2025-04-17T15:50:48.868Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}