Publication Date: 2021-09-14
Last Update: 2021-09-14
Current Version: V1.0
CVSS v3.1 Base Score: 7.2

Affected Product and Versions Remediation
Teamcenter V12.4:
All versions < V12.4.0.8
Update to V12.4.0.8 or later version
https://support.sw.siemens.com/ (login required)
Teamcenter V13.0:
All versions < V13.0.0.7
Update to V13.0.0.7 or later version
https://support.sw.siemens.com/ (login required)
Teamcenter V13.1:
All versions < V13.1.0.5
Update to V13.1.0.5 or later version
https://support.sw.siemens.com/ (login required)
Teamcenter V13.2:
All versions < 13.2.0.2
Update to V13.2.0.2 or later version
https://support.sw.siemens.com/ (login required)

CVSS v3.1 Base Score 7.1
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-267: Privilege Defined With Unsafe Actions

CVSS v3.1 Base Score 7.2
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-639: Authorization Bypass Through User-Controlled Key

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-611: Improper Restriction of XML External Entity Reference

https://www.siemens.com/cert/advisories