CVE-2019-4424: XEE
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162770.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4424?
The severity of CVE-2019-4424 is high with a severity value of 8.2.
How does CVE-2019-4424 impact IBM Business Automation Workflow?
CVE-2019-4424 allows for an XML External Entity Injection (XXE) attack, which can expose sensitive information or consume memory resources in IBM Business Automation Workflow.
What versions of IBM Business Automation Workflow are affected by CVE-2019-4424?
IBM Business Automation Workflow versions 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 are affected by CVE-2019-4424.
How can I fix CVE-2019-4424 in IBM Business Automation Workflow?
To fix CVE-2019-4424 in IBM Business Automation Workflow, apply the necessary security patches or updates provided by IBM.
Are there any additional references for CVE-2019-4424?
Additional references for CVE-2019-4424 can be found at the following links: - [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/162770) - [IBM Security Bulletin](https://www.ibm.com/support/docview.wss?uid=ibm10959537)