First published: Wed May 10 2017(Updated: )
IBM JDK versions 6.0.16.45, 7.0.10.5, 7.1.4.5, and 8.0.4.5 correct a security issue described by upstream as: CVEID: <a href="https://access.redhat.com/security/cve/CVE-2017-1289">CVE-2017-1289</a> DESCRIPTION: IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. CVSS Base Score: 8.2 CVSS Temporal Score: See <a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/125150">https://exchange.xforce.ibmcloud.com/vulnerabilities/125150</a> for the current score CVSS Environmental Score*: Undefined CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L) References: <a href="https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_May_2017">https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_May_2017</a> <a href="http://www-01.ibm.com/support/docview.wss?uid=swg22002169">http://www-01.ibm.com/support/docview.wss?uid=swg22002169</a> <a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/125150">https://exchange.xforce.ibmcloud.com/vulnerabilities/125150</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1449603 is categorized as critical due to its potential for XML External Entity Injection vulnerabilities.
To fix REDHAT-BUG-1449603, upgrade to the patched versions of IBM JDK: 6.0.16.45, 7.0.10.5, 7.1.4.5, or 8.0.4.5.
REDHAT-BUG-1449603 affects IBM JDK versions 6.0, 7.0, and 8.0 prior to the specified patched releases.
CVE-2017-1289 is the identifier for the XML External Entity Injection vulnerability addressed in REDHAT-BUG-1449603.
There are no effective workarounds for REDHAT-BUG-1449603; upgrading to a secure version is the recommended action.