CVE-2023-37364: Ws-Inc J Wbem
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers to read arbitrary files or cause a denial of service, a similar issue to CVE-2013-4152.
Affected products
- Ws-Inc J Wbem: from 4.0.0, before 4.7.5 (fixed in 4.7.5)
Published 2023-08-03. Last modified 2026-06-17.