First published: Fri Sep 28 2018(Updated: )
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Platform Symphony | =7.1-fp1 | |
IBM Platform Symphony | =7.1.1 | |
IBM Spectrum Symphony | =7.1.2 | |
IBM Spectrum Symphony | =7.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1702 is a vulnerability in IBM Platform Symphony and IBM Spectrum Symphony that allows for XML External Entity Injection attacks, potentially leading to exposure of sensitive information or resource consumption.
IBM Platform Symphony versions 7.1 Fix Pack 1 and 7.1.1, as well as IBM Spectrum Symphony versions 7.1.2 and 7.2.0.2 are affected.
CVE-2018-1702 has a severity level of high.
A remote attacker can exploit CVE-2018-1702 by performing an XML External Entity Injection attack.
Yes, you can find references for CVE-2018-1702 at the following links: [https://exchange.xforce.ibmcloud.com/vulnerabilities/146189](https://exchange.xforce.ibmcloud.com/vulnerabilities/146189) and [https://www.ibm.com/support/docview.wss?uid=ibm10719659](https://www.ibm.com/support/docview.wss?uid=ibm10719659).