XML External Entity Injection Vulnerability in IBM Integration Bus and App Connect Products
CVE-2018-1801
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 February 2019
What is CVE-2018-1801?
This vulnerability affects multiple IBM products by allowing a remote attacker to initiate an XML External Entity Injection (XXE) attack during the processing of XML data. By exploiting this vulnerability, attackers can manipulate XML input to consume significant memory resources, potentially leading to degraded performance or unavailability of the affected services. This issue affects specific versions of IBM App Connect, IBM Integration Bus, and WebSphere Message Broker, making it essential for users to apply patches and updates to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
App Connect 11.0.0.0
App Connect 11.0.0.1
Integration Bus 9.0.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved