CVE-2021-20502: XEE
IBM Engineering Lifecycle Optimization - Engineering Insights is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 198059.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is vulnerability CVE-2021-20502?
Vulnerability CVE-2021-20502 refers to an XML External Entity Injection (XXE) attack vulnerability in IBM Engineering Lifecycle Optimization - Engineering Insights.
How severe is CVE-2021-20502?
CVE-2021-20502 has a severity rating of 7.1, which is classified as high.
Which IBM products are affected by CVE-2021-20502?
IBM Engineering Workflow Management (EWM), Rational Team Concert (RTC), Rational Engineering Lifecycle Manager (RELM), Engineering Requirements Quality Assistant On-Premises, Engineering Insights (ENI), and Engineering Lifecycle Management (ELM) versions 6.0.2, 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 are affected by CVE-2021-20502.
How can CVE-2021-20502 be exploited?
CVE-2021-20502 can be exploited by a remote attacker through an XML External Entity Injection (XXE) attack, which can lead to sensitive information exposure or memory resource consumption.
Where can I find more information about CVE-2021-20502?
More information about CVE-2021-20502 can be found at the following references: [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/198059) and [IBM Support Page](https://www.ibm.com/support/pages/node/6437579).