CVE-2022-32755: IBM Security Directory Server external entity injection
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.
Other sources
IBM Security Directory Server is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-32755?
CVE-2022-32755 is a vulnerability in IBM Security Directory Server that allows for an XML External Entity Injection (XXE) attack.
How does CVE-2022-32755 impact IBM Security Directory Server?
CVE-2022-32755 allows a remote attacker to exploit the vulnerability and potentially expose sensitive information or consume memory resources.
What is the severity rating of CVE-2022-32755?
CVE-2022-32755 has a severity rating of 5.5, which is considered medium.
What versions of IBM Security Directory Server are affected by CVE-2022-32755?
IBM Security Directory Server version 6.4.0 is vulnerable to CVE-2022-32755.
How can I fix CVE-2022-32755 in IBM Security Directory Server?
To fix CVE-2022-32755, update IBM Security Directory Server to a version that is not affected by the vulnerability.