CVE-2018-1421: XEE
Published Apr 4, 2018
·Updated
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023.
Affected Software
6 affected components
IBM DataPower Gateway>=7.1.0.0<=7.1.0.21
IBM DataPower Gateway>=7.2.0.0<=7.2.0.18
IBM DataPower Gateway>=7.5.0.0<=7.5.0.13
IBM DataPower Gateway>=7.5.1.0<=7.5.1.12
IBM DataPower Gateway>=7.5.2.0<=7.5.2.12
IBM DataPower Gateway>=7.6.0.0<=7.6.0.5
Remediation
Patch Available
Event History
Apr 4, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2018-1421.
2
What is the severity level of CVE-2018-1421?
The severity level of CVE-2018-1421 is high.
3
What is the affected software for CVE-2018-1421?
The affected software for CVE-2018-1421 is IBM WebSphere DataPower Appliances versions 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6.
4
What is the impact of CVE-2018-1421?
CVE-2018-1421 could be exploited by a remote attacker to expose sensitive information or consume memory resources.
5
Is there a fix available for CVE-2018-1421?
Yes, IBM has released a fix for CVE-2018-1421. Please refer to the IBM support website for more information.