CVE-2023-45192: IBM Engineering Requirements Management DOORS Next XML external entity injection
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 268758.
Other sources
IBM Engineering Requirements Management DOORS Next is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45192?
CVE-2023-45192 is considered a critical vulnerability due to its potential to expose sensitive information through an XML External Entity Injection (XXE) attack.
How do I fix CVE-2023-45192?
To fix CVE-2023-45192, upgrade IBM Engineering Requirements Management DOORS Next to version 7.0.4 or later, which contains the necessary patches.
What types of attacks can exploit CVE-2023-45192?
CVE-2023-45192 can be exploited using XML External Entity Injection (XXE) attacks, allowing for unauthorized access to sensitive data.
Which versions of IBM DOORS Next are affected by CVE-2023-45192?
CVE-2023-45192 affects IBM Engineering Requirements Management DOORS Next versions 7.0.2 and 7.0.3.
What can an attacker gain from exploiting CVE-2023-45192?
By exploiting CVE-2023-45192, an attacker could potentially access sensitive information or exhaust memory resources on the affected system.