First published: Mon Nov 04 2024(Updated: )
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server with Web Server Plug-ins | <=9.0 | |
IBM WebSphere Application Server with Web Server Plug-ins | <=8.5 | |
IBM WebSphere Application Server with Web Server Plug-ins | >=8.5.0.0<8.5.5.27 | |
IBM WebSphere Application Server with Web Server Plug-ins | >=9.0.0.0<9.0.5.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45086 is classified as a high-severity vulnerability due to its potential to expose sensitive information and consume system resources.
To fix CVE-2024-45086, upgrade IBM WebSphere Application Server to the latest version available that addresses this XML external entity injection vulnerability.
CVE-2024-45086 affects users running IBM WebSphere Application Server versions 8.5 and 9.0, specifically up to versions 8.5.5.27 and 9.0.5.22.
CVE-2024-45086 involves an XML External Entity (XXE) injection attack, which can be exploited by privileged users.
Exploiting CVE-2024-45086 could lead to unauthorized exposure of sensitive data and may result in excessive memory consumption on the affected server.