CVE-2023-2139 - CVE House
Back to Database
Status published Medium CVE-2023-2139

Reflected Cross-site Scripting vulnerability affecting DELMIA Apriso Release 2017 through Release 2022

Vulnerability Description

A reflected Cross-site Scripting (XSS) Vulnerability in DELMIA Apriso Release 2017 through Release 2022 allows an attacker to execute arbitrary script code.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2139

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mehdi Elyassa and Vincent Herbulot from Synacktiv

Affected Vendor

Dassault Systèmes

View all reports →

Affected Software

DELMIA Apriso
Vulnerable Versions:
Apriso 2017 Golden, Apriso 2018 Golden, Apriso 2019 Golden, Apriso 2020 Golden, Apriso 2021 Golden, Apriso 2022 Golden

Timeline

Official Publish: April 21st, 2023
Last Modified: February 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Weaknesses (CWE)