XML External Entity Injection Vulnerability in IBM Daeja ViewONE
CVE-2019-4456
7.1HIGH
Summary
IBM Daeja ViewONE products, specifically versions 5.0.5 and 5.0.6, contain a vulnerability that allows for XML External Entity Injection (XXE) when processing XML data. This flaw can be exploited by remote attackers, potentially leading to the disclosure of sensitive information or the exhaustion of memory resources. To mitigate this risk, users are advised to apply the necessary security patches and follow best practices for XML processing.
Affected Version(s)
Daeja ViewONE 5.0.5
Daeja ViewONE 5.0.6
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved