Description
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19915 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, or to conduct a server-side request forgery attack. IBM X-Force ID: 280401. |
References
History
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-01T22:43:34.570Z
Reserved: 2024-01-08T23:42:36.757Z
Link: CVE-2024-22354
Updated: 2024-06-28T20:07:47.845Z
Status : Awaiting Analysis
Published: 2024-04-17T01:15:06.747
Modified: 2024-11-21T08:56:06.303
Link: CVE-2024-22354
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD