First published: Tue Oct 09 2018(Updated: )
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150904.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM FileNet Content Manager | =5.2.1 | |
IBM FileNet Content Manager | =5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-1844.
The affected software is IBM FileNet Content Manager version 5.2.1 and 5.5.0.
The severity of CVE-2018-1844 is high.
The vulnerability allows for XML External Entity Injection (XXE) attacks, which can expose sensitive information or consume memory resources.
Yes, you can find more information at the following references: https://exchange.xforce.ibmcloud.com/vulnerabilities/150904 and https://www.ibm.com/support/docview.wss?uid=ibm10732755.