XML External Entity Injection Vulnerability in IBM Integration Bus and App Connect Products
CVE-2018-1801
5.3MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 4 February 2019
Summary
This vulnerability affects multiple IBM products by allowing a remote attacker to initiate an XML External Entity Injection (XXE) attack during the processing of XML data. By exploiting this vulnerability, attackers can manipulate XML input to consume significant memory resources, potentially leading to degraded performance or unavailability of the affected services. This issue affects specific versions of IBM App Connect, IBM Integration Bus, and WebSphere Message Broker, making it essential for users to apply patches and updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
App Connect 11.0.0.0
App Connect 11.0.0.1
Integration Bus 9.0.0.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved