Security Advisory
CVE-2021-37425
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.