Security Advisory

CVE-2022-34269

8.8
HIGH

Vulnerability Description

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.
Published Date February 29, 2024
Official Source NIST NVD Advisory