CVE-2024-27266: IBM Maximo Application Suite XML external entity injection
IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 284566.
Other sources
IBM Maximo Application Suite is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27266?
CVE-2024-27266 has a medium severity rating due to its potential for information exposure and resource consumption.
How do I fix CVE-2024-27266?
To fix CVE-2024-27266, update IBM Maximo Application Suite to a version higher than 7.6.1.3 that resolves the XML External Entity Injection vulnerability.
What types of attacks are possible with CVE-2024-27266?
CVE-2024-27266 allows a remote attacker to conduct XML External Entity Injection attacks, potentially exposing sensitive information.
Which versions of IBM Maximo are affected by CVE-2024-27266?
Versions of IBM Maximo Application Suite up to and including 7.6.1.3 are vulnerable to CVE-2024-27266.
Who reported CVE-2024-27266?
CVE-2024-27266 was reported by IBM X-Force, with ID 284566.