Description
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
None
Integrity (Vulnerable System)
None
Availability (Vulnerable System)
None
Confidentiality (Subsequent System)
High
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
AU
Y
R
Unchanged
V
D
RE
M
U
Red
Affected products
- PTC / FlexPLM13.0.3.0 – 13.0.3.0
- PTC / FlexPLM11.0 M030 – 11.0 M030
- PTC / FlexPLM11.1 M020 – 11.1 M020
- PTC / FlexPLM11.2.1.0 – 11.2.1.0
- PTC / FlexPLM12.0.0.0 – 12.0.0.0
- PTC / FlexPLM12.0.2.0 – 12.0.2.0
- PTC / FlexPLM12.0.3.0 – 12.0.3.0
- PTC / FlexPLM12.1.2.0 – 12.1.2.0
- PTC / FlexPLM12.1.3.0 – 12.1.3.0
- PTC / FlexPLM13.0.2.0 – 13.0.2.0
- PTC / Windchill PDMLink11.0 M030 – 11.0 M030
- PTC / Windchill PDMLink11.1 M020 – 11.1 M020
- PTC / Windchill PDMLink11.2.1.0 – 11.2.1.0
- PTC / Windchill PDMLink12.0.2.0 – 12.0.2.0
- PTC / Windchill PDMLink12.1.2.0 – 12.1.2.0
- PTC / Windchill PDMLink13.0.2.0 – 13.0.2.0
- PTC / Windchill PDMLink13.1.0.0 – 13.1.0.0
- PTC / Windchill PDMLink13.1.1.0 – 13.1.1.0
- PTC / Windchill PDMLink13.1.2.0 – 13.1.2.0
- PTC / Windchill PDMLink13.1.3.0 – 13.1.3.0
References
Updated 18m ago · 8 sources