8.8
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
Description
Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.
Basic Information
ID
CVE-2025-48006
Source
jpcert
Published
Sep 29, 2025 at 07:40
Affected Product
Vendor
Saison Technology Co.,Ltd.
Product
DataSpider Servista
Version
4.4 and earlier
Affected Versions
Saison Technology Co.,Ltd. DataSpider Servista 4.4 and earlier