First published: Wed Apr 17 2024(Updated: )
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.4 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
>=8.5.0.0<8.5.5.26 | ||
>=9.0.0.0<9.0.5.20 | ||
>=17.0.0.3<24.0.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22354 has been assigned a medium severity level due to its potential impact on sensitive information exposure.
To fix CVE-2024-22354, users should update their IBM WebSphere Application Server to the latest patched version.
CVE-2024-22354 affects IBM WebSphere Application Server versions 8.5, 9.0, and Liberty versions 17.0.0.3 through 24.0.0.5.
Yes, CVE-2024-22354 can be exploited by a remote attacker through XML External Entity Injection.
CVE-2024-22354 is associated with XML External Entity Injection (XXE) attacks.