CVE-2017-1289: XEE
IBM JDK versions 6.0.16.45, 7.0.10.5, 7.1.4.5, and 8.0.4.5 correct a security issue described by upstream as:
CVEID: CVE-2017-1289 DESCRIPTION: IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. CVSS Base Score: 8.2 CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/125150 for the current score CVSS Environmental Score: Undefined CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L)
References:
https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBMSecurityUpdateMay2017 http://www-01.ibm.com/support/docview.wss?uid=swg22002169 https://exchange.xforce.ibmcloud.com/vulnerabilities/125150
Other sources
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 125150.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1289?
The severity of CVE-2017-1289 is classified as High due to the potential exposure of highly sensitive information.
How do I fix CVE-2017-1289?
To fix CVE-2017-1289, update to the latest IBM SDK version that addresses the XML External Entity Injection issue.
What software is affected by CVE-2017-1289?
CVE-2017-1289 affects various versions of IBM SDK, including service refreshes up to version 8.
Can CVE-2017-1289 be exploited remotely?
Yes, CVE-2017-1289 can be exploited remotely by an attacker through XML data processing.
What are the potential impacts of CVE-2017-1289?
The potential impacts of CVE-2017-1289 include exposure of sensitive information and consumption of memory resources.