CVE-2018-1970: XEE
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 153751.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Security Identity Manager vulnerability?
The vulnerability ID for this IBM Security Identity Manager vulnerability is CVE-2018-1970.
What is the severity level of CVE-2018-1970?
The severity level of CVE-2018-1970 is high.
What is the description of the CVE-2018-1970 vulnerability?
The CVE-2018-1970 vulnerability is an XML External Entity Injection (XXE) attack vulnerability in IBM Security Identity Manager 7.0.1, which can be exploited by a remote attacker to expose sensitive information or consume memory resources.
How does CVE-2018-1970 affect IBM Security Identity Manager?
CVE-2018-1970 affects IBM Security Identity Manager 7.0.1 and can be exploited to perform XML External Entity Injection (XXE) attacks.
Are there any references for CVE-2018-1970?
Yes, the references for CVE-2018-1970 are: [link1] [link2]