CVE-2021-37254

In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:m-files:m-files_web:*:*:*:*:*:*:*:*
cpe:2.3:a:m-files:m-files_web:*:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-287 NVD-CWE-noinfo

02 Nov 2021, 14:58

Type Values Removed Values Added
CPE cpe:2.3:a:m-files:m-files_web:*:*:*:*:*:*:*:*
References (MISC) https://www.m-files.com/company/trust-center/vulnerability-disclosure/ - (MISC) https://www.m-files.com/company/trust-center/vulnerability-disclosure/ - Vendor Advisory
References (MISC) https://www.m-files.com/about/trust-center/security-vulnerabilities/cve-2021-37254/ - (MISC) https://www.m-files.com/about/trust-center/security-vulnerabilities/cve-2021-37254/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-287

28 Oct 2021, 14:26

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-28 14:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-37254

Mitre link : CVE-2021-37254

CVE.ORG link : CVE-2021-37254


JSON object : View

Products Affected

m-files

  • m-files_web