First published: Fri Jul 06 2018(Updated: )
IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 142597.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FileNet Content Manager | =5.2.1 | |
IBM FileNet Content Manager | =5.5.0 | |
IBM Content Foundation | =5.2.1 | |
IBM Content Foundation | =5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1542 is a vulnerability in IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 that allows a remote attacker to exploit an XML External Entity Injection (XXE) vulnerability.
IBM FileNet Content Manager 5.2.1 and 5.5.0, IBM Content Foundation 5.2.1 and 5.5.0, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.0 are affected by CVE-2018-1542.
CVE-2018-1542 has a severity rating of 7.1 (high).
A remote attacker can exploit CVE-2018-1542 by performing an XML External Entity Injection (XXE) attack when processing XML data.
Yes, here are some references for CVE-2018-1542: - [IBM Support](http://www.ibm.com/support/docview.wss?uid=swg22015943) - [SecurityTracker](http://www.securitytracker.com/id/1041225) - [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/142597)