CVE-2024-45086: IBM WebSphere Application Server XML external entity injection
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM WebSphere Application Server is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45086?
CVE-2024-45086 is classified as a high-severity vulnerability due to its potential to expose sensitive information and consume system resources.
How do I fix CVE-2024-45086?
To fix CVE-2024-45086, upgrade IBM WebSphere Application Server to the latest version available that addresses this XML external entity injection vulnerability.
Who is affected by CVE-2024-45086?
CVE-2024-45086 affects users running IBM WebSphere Application Server versions 8.5 and 9.0, specifically up to versions 8.5.5.27 and 9.0.5.22.
What type of attack does CVE-2024-45086 involve?
CVE-2024-45086 involves an XML External Entity (XXE) injection attack, which can be exploited by privileged users.
What could be the impact of exploiting CVE-2024-45086?
Exploiting CVE-2024-45086 could lead to unauthorized exposure of sensitive data and may result in excessive memory consumption on the affected server.