XML External Entity Injection Vulnerability in IBM Content Management Solutions
CVE-2018-1542
7.1HIGH
What is CVE-2018-1542?
IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine versions 5.2.1 and 5.5.0 are susceptible to an XML External Entity Injection (XXE) vulnerability. This occurs when the products process XML data that may allow a remote attacker to exploit this weakness. Successful exploitation could result in the unauthorized exposure of sensitive information and excessive consumption of system memory resources, potentially leading to denial of service.
Affected Version(s)
FileNet P8 Platform 5.2.1
FileNet P8 Platform 5.5.0