First published: Tue Jul 30 2019(Updated: )
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 163620.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Daeja ViewONE | >=5.0<=5.0.6 | |
IBM Daeja ViewONE | >=5.0<=5.0.6 | |
IBM Daeja ViewONE | >=5.0<=5.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4456 is a vulnerability that affects IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6. It allows for an XML External Entity Injection (XXE) attack that can expose sensitive information or consume memory resources.
CVE-2019-4456 allows remote attackers to exploit the vulnerability and potentially expose sensitive information or consume memory resources in IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6.
The severity of CVE-2019-4456 is high with a CVSS score of 7.1.
An attacker can exploit CVE-2019-4456 by sending specially crafted XML data to IBM Daeja ViewONE, triggering an XML External Entity (XXE) injection.
Yes, IBM has released a security bulletin with fixes and mitigations for the vulnerability. Please refer to the IBM support document for more information.