First published: Thu Aug 31 2017(Updated: )
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128377.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM QRadar Network Security | =5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1458 is considered a high-severity vulnerability that allows for XML External Entity Injection.
To address CVE-2017-1458, update IBM QRadar Network Security to the latest patched version provided by IBM.
CVE-2017-1458 can be exploited by remote attackers to expose sensitive information or consume excessive memory resources.
CVE-2017-1458 affects IBM QRadar Network Security version 5.4, so systems running this version are vulnerable.
XML External Entity Injection allows attackers to access internal files or services and potentially disclose sensitive information.