CVE-2017-1219: XEE
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 123859.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1219?
CVE-2017-1219 has a moderate severity rating due to potential unauthorized access to sensitive information.
How do I fix CVE-2017-1219?
To remediate CVE-2017-1219, update IBM Tivoli Endpoint Manager to the latest version that addresses the XML External Entity Injection vulnerability.
Which versions of IBM Tivoli Endpoint Manager are affected by CVE-2017-1219?
CVE-2017-1219 affects IBM Tivoli Endpoint Manager versions 9.1.x and 9.2.x.
What kind of attack does CVE-2017-1219 allow?
CVE-2017-1219 allows a remote attacker to perform an XML External Entity (XXE) attack.
What can be exposed due to CVE-2017-1219?
CVE-2017-1219 can potentially expose sensitive information or consume memory resources on the affected system.