CVE-2021-20482: XEE
IBM Business Automation Workflow is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 197504.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-20482.
What is the severity of CVE-2021-20482?
The severity of CVE-2021-20482 is high with a CVSS score of 7.1.
What is the affected software?
The affected software is IBM Cloud Pak for Automation versions 20.0.2 and 20.0.3 IF002.
What is the impact of CVE-2021-20482?
CVE-2021-20482 allows a remote attacker to expose sensitive information or consume memory resources through an XML External Entity Injection (XXE) attack.
Are there any known fixes or mitigations for CVE-2021-20482?
Yes, IBM has provided a fix for this vulnerability. Please refer to the IBM support page for more details.