Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31559 | Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur. |
Tue, 14 Oct 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:saison:dataspider_servista:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 30 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Saison
Saison dataspider Servista |
|
| Vendors & Products |
Saison
Saison dataspider Servista |
Mon, 29 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Sep 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur. | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-09-29T11:44:58.304Z
Reserved: 2025-09-24T00:48:29.080Z
Link: CVE-2025-48006
Updated: 2025-09-29T11:44:09.215Z
Status : Analyzed
Published: 2025-09-29T08:15:35.037
Modified: 2025-10-14T18:18:55.560
Link: CVE-2025-48006
No data.
OpenCVE Enrichment
Updated: 2025-09-30T08:48:31Z
EUVD