First published: Fri Oct 29 2021(Updated: )
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server | =11.7 | |
IBM AIX | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Ibm Infosphere Information Server | <=11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue in IBM InfoSphere Information Server is CVE-2021-38948.
The severity rating of the CVE-2021-38948 vulnerability is 9.1 (critical).
In CVE-2021-38948, the XML External Entity Injection (XXE) attack occurs when processing XML data, allowing remote attackers to expose sensitive information or consume memory resources.
The version 11.7 of IBM InfoSphere Information Server is affected by CVE-2021-38948.
Yes, there is a patch available for CVE-2021-38948. You can find it at the following URL: [https://www.ibm.com/support/pages/node/878310](https://www.ibm.com/support/pages/node/878310)