---
id: CVE-2025-48006
title: >-
  Improper restriction of XML external entity reference issue exists in
  DataSpider Servista 4.4 and earlier
summary: >-
  Improper restriction of XML external entity reference issue exists in
  DataSpider Servista 4.4 and earlier. If a specially crafted request is
  processed, arbitrary files on the file system where the server application for
  the product is in…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-611
vendor: saison
product: dataspider_servista
affected:
  - dataspider_servista <= 4.4
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48006'
references:
  - url: 'https://jvn.jp/en/jp/JVN23423519/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://www.hulft.com/application/files/1217/5885/0217/information_20250926.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00539
epssPercentile: 0.43573
ingestedAt: '2026-10-09T09:31:00.981Z'
---

## Overview

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.

## Affected

- `dataspider_servista <= 4.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
