XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote authenticated users to read arbitrary files or cause a denial of service via crafted XML data. IBM X-Force ID: 110510.
2018-03-12T21:29:00.390
2024-11-21T02:41:21.683
Modified
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:P
8.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | infosphere_information_server | < 11.3.1.2 | Yes |
| Application | ibm | infosphere_information_server | 11.5 | Yes |