First published: Wed Feb 21 2018(Updated: )
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =3.0.2.0 | |
Ibm Financial Transaction Manager | =3.0.2.0 | |
Ibm Financial Transaction Manager | =3.0.2.1 | |
Ibm Financial Transaction Manager | =3.0.3.0 | |
Ibm Financial Transaction Manager | =3.0.4.0 | |
Ibm Financial Transaction Manager | =3.1.0.0 | |
IBM Transformation Extender Advanced | =9.0 | |
IBM Control Center | =6.0.0.0 | |
IBM Control Center | =6.0.0.1 | |
IBM Control Center | =6.1.0.0 | |
IBM Control Center | =6.1.0.1 | |
IBM Control Center | =6.1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1758 is a vulnerability in IBM Financial Transaction Manager for ACH Services and IBM Control Center that allows XML External Entity Injection (XXE) attacks.
CVE-2017-1758 has a severity rating of 7.1 (High).
IBM Financial Transaction Manager versions 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Control Center 6.0 and 6.1, and IBM Transformation Extender Advanced 9.0 are affected by CVE-2017-1758.
Apply the necessary security patches provided by IBM to fix CVE-2017-1758.
You can find more information about CVE-2017-1758 on the IBM support website using the provided references: [1], [2], [3].