CVE-2019-4707: XEE
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.
Other sources
IBM Security Access Manager Appliance is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-4707.
What is the title of the vulnerability?
The title of the vulnerability is IBM Security Access Manager Appliance is vulnerable to an XML External Entity Injection (XXE) attack.
What is the severity level of CVE-2019-4707?
The severity level of CVE-2019-4707 is high (7.1).
How can this vulnerability be exploited?
This vulnerability can be exploited through an XML External Entity Injection (XXE) attack when processing XML data.
Is there a patch available for this vulnerability?
Yes, IBM has released a patch for this vulnerability. You can download it from the official IBM Support website.