XML External Entity Injection Vulnerability in IBM Integration Bus and App Connect Products
CVE-2018-1801

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
4 February 2019

Summary

This vulnerability affects multiple IBM products by allowing a remote attacker to initiate an XML External Entity Injection (XXE) attack during the processing of XML data. By exploiting this vulnerability, attackers can manipulate XML input to consume significant memory resources, potentially leading to degraded performance or unavailability of the affected services. This issue affects specific versions of IBM App Connect, IBM Integration Bus, and WebSphere Message Broker, making it essential for users to apply patches and updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

App Connect 11.0.0.0

App Connect 11.0.0.1

Integration Bus 9.0.0.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.