First published: Mon Jan 29 2018(Updated: )
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 137449.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | =2.0.3 | |
IBM Content Navigator | =3.0.2 | |
IBM Content Navigator | =3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1364 is a vulnerability in IBM Content Navigator 2.0 and 3.0 that allows for XML External Entity Injection (XXE) attacks.
CVE-2018-1364 affects IBM Content Navigator 2.0.3, 3.0.2, and 3.0.3.
The severity of CVE-2018-1364 is rated as high with a CVSS score of 8.2.
An XML External Entity Injection (XXE) attack is a vulnerability that allows an attacker to read local files, perform server-side request forgery (SSRF) attacks, or consume excessive memory by exploiting the processing of XML data.
To mitigate CVE-2018-1364, apply the necessary patches or updates provided by IBM to ensure the vulnerability is fixed.