An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity resolution, allowing crafted SAML responses to invoke external entity references. This could enable attackers to retrieve sensitive files or perform server-side request forgery (SSRF). The issue was addressed by disabling external entity processing for the affected XML parser in versions SE.2025.1 and 2025.1.2.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 22 Jul 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity resolution, allowing crafted SAML responses to invoke external entity references. This could enable attackers to retrieve sensitive files or perform server-side request forgery (SSRF). The issue was addressed by disabling external entity processing for the affected XML parser in versions SE.2025.1 and 2025.1.2. | |
Title | ETQ Reliance CG XML External Entity (XXE) Injection in SSO SAML Handler | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-22T12:31:58.875Z
Updated: 2025-07-22T13:29:08.545Z
Reserved: 2025-04-15T19:15:22.563Z
Link: CVE-2025-34142

Updated: 2025-07-22T13:29:01.298Z

Status : Awaiting Analysis
Published: 2025-07-22T13:15:24.970
Modified: 2025-07-25T15:29:44.523
Link: CVE-2025-34142

No data.