All the vulnerabilites related to Financial Services Agency - XBRL data create application
jvndb-2023-000072
Vulnerability from jvndb
Published
2023-07-18 15:22
Modified
2024-03-19 18:11
Severity ?
Summary
Improper restriction of XML external entity references (XXE) in XBRL data create application
Details
XBRL data create application provided by Financial Services Agency improperly restricts XML external entity references (XXE) (CWE-611). Taku Toyama of NEC Corporation reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-000072.html",
  "dc:date": "2024-03-19T18:11+09:00",
  "dcterms:issued": "2023-07-18T15:22+09:00",
  "dcterms:modified": "2024-03-19T18:11+09:00",
  "description": "XBRL data create application provided by Financial Services Agency improperly restricts XML external entity references (XXE) (CWE-611).\r\n\r\nTaku Toyama of NEC Corporation reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
  "link": "https://jvndb.jvn.jp/en/contents/2023/JVNDB-2023-000072.html",
  "sec:cpe": {
    "#text": "cpe:/a:edinet-fsa:xbrl_data_create",
    "@product": "XBRL data create application",
    "@vendor": "Financial Services Agency",
    "@version": "2.2"
  },
  "sec:cvss": [
    {
      "@score": "1.2",
      "@severity": "Low",
      "@type": "Base",
      "@vector": "AV:L/AC:H/Au:N/C:P/I:N/A:N",
      "@version": "2.0"
    },
    {
      "@score": "2.5",
      "@severity": "Low",
      "@type": "Base",
      "@vector": "CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "@version": "3.0"
    }
  ],
  "sec:identifier": "JVNDB-2023-000072",
  "sec:references": [
    {
      "#text": "https://jvn.jp/en/jp/JVN44726469/index.html",
      "@id": "JVN#44726469",
      "@source": "JVN"
    },
    {
      "#text": "https://www.cve.org/CVERecord?id=CVE-2023-32635",
      "@id": "CVE-2023-32635",
      "@source": "CVE"
    },
    {
      "#text": "https://nvd.nist.gov/vuln/detail/CVE-2023-32635",
      "@id": "CVE-2023-32635",
      "@source": "NVD"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-Other",
      "@title": "No Mapping(CWE-Other)"
    }
  ],
  "title": "Improper restriction of XML external entity references (XXE) in XBRL data create application"
}

cve-2023-32635
Vulnerability from cvelistv5
Published
2023-07-19 05:54
Modified
2024-10-28 15:02
Severity ?
Summary
XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker.
Impacted products
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T15:25:35.706Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://submit2.edinet-fsa.go.jp/"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN44726469/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-32635",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-28T15:02:38.034691Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-28T15:02:48.513Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "XBRL data create application",
          "vendor": "Financial Services Agency",
          "versions": [
            {
              "status": "affected",
              "version": "version 7.0 and earlier"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBRL file, arbitrary files on the system may be read by an attacker."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "XML external entities (XXE)",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-07-19T05:54:29.352Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "url": "https://submit2.edinet-fsa.go.jp/"
        },
        {
          "url": "https://jvn.jp/en/jp/JVN44726469/"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2023-32635",
    "datePublished": "2023-07-19T05:54:29.352Z",
    "dateReserved": "2023-05-11T04:09:45.906Z",
    "dateUpdated": "2024-10-28T15:02:48.513Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}