First published: Mon Jun 17 2019(Updated: )
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.3 | |
Ibm Infosphere Information Server | =11.5 | |
Ibm Infosphere Information Server | =11.7 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Ibm Infosphere Governance Catalog | =11.3 | |
Ibm Infosphere Governance Catalog | =11.5 | |
Ibm Infosphere Governance Catalog | =11.7 | |
Ibm Infosphere Information Server On Cloud | =11.5 | |
Ibm Infosphere Information Server On Cloud | =11.7 | |
Ibm Infosphere Information Server Business Glossary | =9.1 | |
IBM InfoSphere Information Server Metadata Workbench | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-1845.
The severity of this vulnerability is high with a severity value of 7.1.
IBM InfoSphere Information Server versions 11.3, 11.5, and 11.7 are affected by this vulnerability.
This vulnerability could be exploited by a remote attacker to expose sensitive information or consume memory resources.
Yes, IBM has released a fix for this vulnerability. Please refer to the IBM Security Bulletin for more information.