First published: Wed May 10 2023(Updated: )
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Websphere Application Server | >=8.5.0.0<8.5.5.24 | |
Ibm Websphere Application Server | >=9.0.0.0<9.0.5.16 | |
<=9.0 | ||
<=8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27554 is a vulnerability in IBM WebSphere Application Server that allows for an XML External Entity Injection (XXE) attack, which can lead to the exposure of sensitive information or the consumption of memory resources.
The XML External Entity Injection (XXE) attack occurs when an attacker exploits a vulnerability to inject malicious XML entities into the application, allowing them to read sensitive data or consume system resources.
IBM WebSphere Application Server versions 8.5 and 9.0 are affected by CVE-2023-27554.
CVE-2023-27554 has a severity rating of 9.1 (critical).
To mitigate the CVE-2023-27554 vulnerability, apply the necessary security patches provided by IBM, and ensure that the XML processing in the application is secure and properly configured.