CVE-2018-1845: XEE
Published Jun 17, 2019
·Updated
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
Affected Software
13 affected components
IBM InfoSphere Information Server=11.3
IBM InfoSphere Information Server=11.5
IBM InfoSphere Information Server=11.7
IBM AIX
Linux Linux kernel
Microsoft Windows
IBM Infosphere Governance Catalog=11.3
IBM Infosphere Governance Catalog=11.5
IBM Infosphere Governance Catalog=11.7
IBM Infosphere Information Server On Cloud=11.5
IBM Infosphere Information Server On Cloud=11.7
IBM InfoSphere Information Server Business Glossary=9.1
IBM InfoSphere Information Server Metadata Workbench=9.1
Remediation
Patch Available
Event History
Jun 17, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-1845.
2
What is the severity of this vulnerability?
The severity of this vulnerability is high with a severity value of 7.1.
3
Which software versions are affected by this vulnerability?
IBM InfoSphere Information Server versions 11.3, 11.5, and 11.7 are affected by this vulnerability.
4
What is the impact of this vulnerability?
This vulnerability could be exploited by a remote attacker to expose sensitive information or consume memory resources.
5
Is there a fix available for this vulnerability?
Yes, IBM has released a fix for this vulnerability. Please refer to the IBM Security Bulletin for more information.