VendorsAltovamobiletogether_serverall versions
Vulnerabilities

Altova MobileTogether Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-37425
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
Published 2021-08-10 · Modified
9.11 PoCEPSS 0.663
CVE-2021-38490
Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.
Published 2021-08-10 · Modified
7.5EPSS 0.010