First published: Mon Sep 20 2021(Updated: )
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 204775.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Jazz for Service Management | =1.1.3.10 | |
Ibm Tivoli Netcool\/omnibus Gui | =1.1.3.10 | |
IBM Jazz for Service Management | <=1.1.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29831 is a vulnerability in IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI that allows for an XML External Entity Injection (XXE) attack.
The severity of CVE-2021-29831 is high with a CVSS score of 8.1.
CVE-2021-29831 allows remote attackers to exploit an XML External Entity Injection (XXE) vulnerability in IBM Jazz for Service Management, potentially exposing sensitive information or consuming memory resources.
CVE-2021-29831 allows remote attackers to exploit an XML External Entity Injection (XXE) vulnerability in IBM Tivoli Netcool/OMNIbus_GUI, potentially exposing sensitive information or consuming memory resources.
To mitigate the vulnerabilities in IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI, it is recommended to apply the necessary security updates provided by IBM.