A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (XXE) vulnerability in the docx import feature. This could allow an authenticated remote attacker to read arbitrary data from the application server.
History

Tue, 23 Sep 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens polarion Alm
CPEs cpe:2.3:a:siemens:polarion_alm:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:polarion_alm:2310.0:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens polarion Alm

Tue, 13 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XML External Entity Injection (XXE) vulnerability in the docx import feature. This could allow an authenticated remote attacker to read arbitrary data from the application server.
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2025-05-13T09:38:22.679Z

Updated: 2025-05-13T19:02:54.611Z

Reserved: 2024-10-28T07:01:23.766Z

Link: CVE-2024-51445

cve-icon Vulnrichment

Updated: 2025-05-13T19:02:44.337Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-13T10:15:21.527

Modified: 2025-09-23T15:34:45.677

Link: CVE-2024-51445

cve-icon Redhat

No data.