XML External Entity Injection Vulnerability in IBM Integration Bus and App Connect Products
CVE-2018-1801
5.3MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 February 2019
What is CVE-2018-1801?
This vulnerability affects multiple IBM products by allowing a remote attacker to initiate an XML External Entity Injection (XXE) attack during the processing of XML data. By exploiting this vulnerability, attackers can manipulate XML input to consume significant memory resources, potentially leading to degraded performance or unavailability of the affected services. This issue affects specific versions of IBM App Connect, IBM Integration Bus, and WebSphere Message Broker, making it essential for users to apply patches and updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
App Connect 11.0.0.0
App Connect 11.0.0.1
Integration Bus 9.0.0.0