CVE-2018-1905: XEE
IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152534.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1905?
CVE-2018-1905 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2018-1905?
To fix CVE-2018-1905, upgrade your IBM WebSphere Application Server to version 9.0.0.10 or later.
Who is affected by CVE-2018-1905?
CVE-2018-1905 affects users of IBM WebSphere Application Server versions from 9.0.0.0 to 9.0.0.9.
What type of attack does CVE-2018-1905 allow?
CVE-2018-1905 allows attackers to perform XML External Entity Injection (XXE) attacks.
What can attackers achieve by exploiting CVE-2018-1905?
By exploiting CVE-2018-1905, attackers can expose sensitive information or consume system memory resources.