IBM DOORS Web Access Vulnerable to XML External Entity Injection Attack
CVE-2023-50304
8.2HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 18 July 2024
What is CVE-2023-50304?
IBM Engineering Requirements Management DOORS Web Access version 9.7.2.8 is susceptible to an XML External Entity Injection (XXE) attack during the processing of XML data. This flaw can be leveraged by remote attackers to expose confidential information or exhaust memory resources, potentially leading to a disruption in service and data breaches. Organizations utilizing this product are encouraged to implement appropriate security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Engineering Requirements Management DOORS 9.7.2.8