XML External Entity Injection Vulnerability in IBM Security Access Manager for Enterprise Single Sign-On
CVE-2019-4513
8.2HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 26 August 2019
What is CVE-2019-4513?
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is susceptible to an XML External Entity Injection (XXE) attack, enabling a remote attacker to manipulate XML data processing. Exploiting this vulnerability could lead to the unauthorized disclosure of sensitive information or the consumption of memory resources, potentially impacting system performance and data integrity.
Affected Version(s)
Security Access Manager for Enterprise Single Sign-On 8.2.2