IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-31308 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 249185. |
Fri, 24 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-01-24T16:13:22.107Z
Reserved: 2023-03-02T20:39:33.983Z
Link: CVE-2023-27554
Updated: 2024-08-02T12:16:35.625Z
Status : Modified
Published: 2023-05-11T20:15:09.227
Modified: 2025-01-24T17:15:11.073
Link: CVE-2023-27554
No data.
OpenCVE Enrichment
No data.
EUVD